


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was identified in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598. Impacted is the function search_papers of the file src/ma…
Published:
27 April 2026 at 22:00:00
Alert date:
28 April 2026 at 02:02:55
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A path traversal vulnerability was identified in duartium papers-mcp-server affecting the search_papers function in src/main.py. The vulnerability allows remote attackers to manipulate the topic argument to perform path traversal attacks. An exploit is publicly available and the attack can be launched remotely. The project maintainers were notified through an issue report but have not responded yet. This represents an actively exploitable vulnerability with public proof-of-concept code available.
Technical details
Mitigation steps:
Affected products:
duartium papers-mcp-server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7205
https://github.com/duartium/papers-mcp-server/
https://github.com/duartium/papers-mcp-server/issues/1
https://vuldb.com/submit/802080
https://vuldb.com/vuln/359805
https://vuldb.com/vuln/359805/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
