CVE-2026-15528: Lamaalrajih Kicad-Mcp

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manipulation of the argument project_path/schematic_path results in protection mechanism failure. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected products

  • Lamaalrajih Kicad-Mcp: version 3.3.0 only; version 3.3.1 only

Published 2026-07-13. Last modified 2026-07-13.