CVE-2026-7594
Last modified
CVE-2026-7594 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. A vulnerability was detected in Flux159 mcp-game-asset-gen 0.1.0. Affected is the function image_to_3d_async of the file src/index.ts of the component MCP Interface. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
A vulnerability was detected in Flux159 mcp-game-asset-gen 0.1.0. Affected is the function image_to_3d_async of the file src/index.ts of the component MCP Interface. The manipulation of the argument statusFile results in path traversal. The attack can be executed remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-7594?
How severe is CVE-2026-7594?
How do I fix CVE-2026-7594?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-75931fast-uri is a URI parser for Node.js. It canonicalizes a hos…7.5
- CVE-2026-75932Jet Admin allows an attacker to create a malicious app and c…8.6
- CVE-2026-75933Jet Admin allows an authenticated attacker to inject JavaScr…7.3
- CVE-2026-75935Uncontrolled memory allocation in the binary Ion stream curs…7.5
- CVE-2026-75936Improper handling of highly compressed data in the GZIP auto…7.5
- CVE-2026-75939A flaw was found in openshift/oc-mirror. The tool incorrectl…7.4
- CVE-2026-75940A vulnerability was reported in Lenovo Health Android Applic…9.1
- CVE-2026-75943A brief (milliseconds to seconds) traffic leak may occur whe…2.6
- CVE-2026-75944A race condition during supplicant re-authentication may lea…2.6
- CVE-2026-75945A race condition may cause a supplicant to remain in an auth…2.6
- CVE-2026-75946A potential security vulnerability has been identified in th…8.2
- CVE-2026-75948Joomla Extension - icagenda.com - Authenticated Stored XSS …8.6
Are you affected by CVE-2026-7594?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
