A vulnerability was found in Ichigo3766 image-gen-mcp 0.1.0. It has been declared as critical. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation of the argument output_path leads to path traversal.

This vulnerability is listed as CVE-2026-19365. The attack must be carried out locally. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.