A vulnerability was found in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598 and classified as critical. Impacted is the function
search_papers of the file src/main.py. Such manipulation of the argument topic leads to path traversal.
This vulnerability is traded as CVE-2026-7205. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.