216.73.217.22

CVE-2026-7403

· Published 29/04/2026 21:16 · Modified 29/04/2026 21:16

Labels: CVE-2026-7403 2026-04-29CVE-2026-7403CWE-22[email protected]

Essential information

Published
29/04/2026 21:16
Modified
29/04/2026 21:16
Author
Creator
CVSS
5.5 MEDIUM (v3) 5.5 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The manipulation of the argument rule_name results in path traversal. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

NVD status

Status
Deferred — When a CVE is given this status the NVD does not plan analyze or re-analyze this CVE due to resource or other concerns.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
geldata / gel-mcp cpe:2.3:a:geldata:gel-mcp:0.1.0:*:*:*:*:*:*:*

References