A vulnerability classified as critical was found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function
getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of the argument skillName leads to path traversal.
This vulnerability is referenced as CVE-2026-19335. The attack can only be performed from a local environment. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.