A vulnerability identified as critical has been detected in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This manipulation of the argument ID causes path traversal.
This vulnerability is registered as CVE-2026-19287. The attack needs to be launched locally. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.