


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The affected element is the function update_do…
Published:
4 mei 2026 om 22:00:00
Alert date:
5 mei 2026 om 20:13:49
Source:
nvd.nist.gov
Web Technologies
A path traversal vulnerability (CVE-2026-7788) has been discovered in Axle-Bucamp MCP-Docusaurus affecting document management functions in app/routes/document.py. The vulnerability allows remote attackers to manipulate the DOCS_DIR/path argument to perform path traversal attacks. Multiple functions are affected including update_document, continue_document, delete_document, and get_content. The exploit has been publicly released and can be used for active attacks. The project maintainers have been notified through an issue report but have not yet responded. Due to the rolling release model, specific version information is not available.
Technical details
Mitigation steps:
Affected products:
Axle-Bucamp MCP-Docusaurus
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7788
https://github.com/Axle-Bucamp/MCP-Docusaurus/
https://github.com/Axle-Bucamp/MCP-Docusaurus/issues/2
https://vuldb.com/submit/807746
https://vuldb.com/vuln/360994
https://vuldb.com/vuln/360994/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
