top of page
perceptive_background_267k.jpg

A vulnerability was detected in Flux159 mcp-game-asset-gen 0.1.0. Affected is the function image_to_3d_async of the file src/index.ts of the component MCP Inter…

Published:

30 april 2026 om 22:00:00

Alert date:

1 mei 2026 om 22:01:21

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

A path traversal vulnerability (CVE-2026-7594) has been discovered in Flux159 mcp-game-asset-gen version 0.1.0. The vulnerability affects the image_to_3d_async function in src/index.ts of the MCP Interface component. Attackers can manipulate the statusFile argument to achieve path traversal. The attack can be executed remotely and the exploit is publicly available. The project maintainers were notified through an issue report but have not responded yet.

Technical details

Mitigation steps:

Affected products:

Flux159 mcp-game-asset-gen

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page