


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_c…
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 21:20:20
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A path traversal vulnerability has been discovered in WilliamCloudQi matlab-mcp-server up to commit ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The flaw affects the generate_matlab_code/execute_matlab_code functions in src/index.ts of the MCP Interface component. Attackers can manipulate the scriptPath argument to achieve path traversal. The vulnerability can be exploited remotely and a public exploit has been published. The project maintainers have been notified through an issue report but have not yet responded to the security disclosure.
Technical details
Mitigation steps:
Affected products:
WilliamCloudQi matlab-mcp-server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7272
https://github.com/BruceJqs/public_exp/issues/18
https://github.com/WilliamCloudQi/matlab-mcp-server/
https://github.com/WilliamCloudQi/matlab-mcp-server/issues/8
https://vuldb.com/submit/802911
https://vuldb.com/vuln/359927
https://vuldb.com/vuln/359927/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
