CVE-2026-19338: Automateyournetwork Mcpyats

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal. The attack must be carried out locally.

Affected products

  • Automateyournetwork Mcpyats: version 0.1.0 only; version 0.1.1 only; version 0.1.2 only; version 0.1.3 only; version 0.1.4 only

Published 2026-08-09. Last modified 2026-08-12.