


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was detected in Flux159 mcp-game-asset-gen 0.1.0. Affected is the function image_to_3d_async of the file src/index.ts of the component MCP Inter…
Published:
30 April 2026 at 22:00:00
Alert date:
1 May 2026 at 22:01:21
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A path traversal vulnerability (CVE-2026-7594) has been discovered in Flux159 mcp-game-asset-gen version 0.1.0. The vulnerability affects the image_to_3d_async function in src/index.ts of the MCP Interface component. Attackers can manipulate the statusFile argument to achieve path traversal. The attack can be executed remotely and the exploit is publicly available. The project maintainers were notified through an issue report but have not responded yet.
Technical details
Mitigation steps:
Affected products:
Flux159 mcp-game-asset-gen
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7594
https://github.com/Flux159/mcp-game-asset-gen/
https://github.com/Flux159/mcp-game-asset-gen/issues/3
https://vuldb.com/submit/805508
https://vuldb.com/vuln/360547
https://vuldb.com/vuln/360547/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
