A vulnerability, which was classified as critical, has been found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function
ApprovalStorage.createApproval of the file src/tools/approvals.ts. Performing a manipulation of the argument categoryName results in path traversal.
This vulnerability is identified as CVE-2026-19336. The attack is only possible with local access. There is not any exploit available.
It is advisable to upgrade the affected component.