


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_documents of the file server.py. Performing a ma…
Published:
26 april 2026 om 22:00:00
Alert date:
27 april 2026 om 23:01:40
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A path traversal vulnerability was discovered in douinc mkdocs-mcp-plugin up to version 0.4.1. The vulnerability affects the read_document and list_documents functions in server.py, allowing attackers to manipulate the docs_dir/file_path arguments to perform directory traversal attacks. The vulnerability can be exploited remotely and a public exploit is available. The vendor has acknowledged the issue and confirmed that a fix will be published within a few days.
Technical details
Mitigation steps:
Affected products:
douinc mkdocs-mcp-plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7159
https://github.com/douinc/mkdocs-mcp-plugin/
https://github.com/douinc/mkdocs-mcp-plugin/issues/6
https://github.com/douinc/mkdocs-mcp-plugin/issues/6#issuecomment-4223718119
https://vuldb.com/submit/802063
https://vuldb.com/vuln/359758
https://vuldb.com/vuln/359758/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
