CVE-2026-14702 Details
Description
A flaw has been found in zcaceres markdownify-mcp up to 1.1.0. This impacts the function saveToTempFile of the file src/Markdownify.ts of the component webpage-to-markdown/youtube-to-markdown/bing-search-to-markdown. This manipulation causes insufficiently random values. The attack is restricted to local execution. A high degree of complexity is needed for the attack. The exploitability is said to be difficult. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
A vulnerability exists in zcaceres markdownify-mcp versions through 1.1.0, specifically in the function saveToTempFile within src/Markdownify.ts. The issue arises from a predictable temporary file path used when converting web content to Markdown, which can lead to symlink overwriting and data leakage. This vulnerability requires local execution to exploit and involves a high level of complexity.
Users are advised to update to the latest version of markdownify-mcp, where this issue has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 5, 2026CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zcaceres/markdownify-mcp/ | [email protected] | Source CodeVendor |
| https://github.com/zcaceres/markdownify-mcp/issues/110 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/zcaceres/markdownify-mcp/pull/111 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-14702 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/846942 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/376298 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/376298/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-310 | Cryptographic Issues | [email protected] |
| CWE-330 | Use of Insufficiently Random Values | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zcaceres markdownify-mcp | <= 1.1.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 5, 2026 | New CVE Received | [email protected] |
Volerion