top of page
perceptive_background_267k.jpg

A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The affected element is the function update_do…

Published:

4 May 2026 at 22:00:00

Alert date:

5 May 2026 at 20:13:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

A path traversal vulnerability (CVE-2026-7788) has been discovered in Axle-Bucamp MCP-Docusaurus affecting document management functions in app/routes/document.py. The vulnerability allows remote attackers to manipulate the DOCS_DIR/path argument to perform path traversal attacks. Multiple functions are affected including update_document, continue_document, delete_document, and get_content. The exploit has been publicly released and can be used for active attacks. The project maintainers have been notified through an issue report but have not yet responded. Due to the rolling release model, specific version information is not available.

Technical details

Mitigation steps:

Affected products:

Axle-Bucamp MCP-Docusaurus

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page