CVE-2026-7214 Details
Description
A vulnerability was identified in eghuzefa engineer-your-data up to 0.1.3. This vulnerability affects the function read_file/write_file/list_files/file_inf of the file src/server.py. The manipulation of the argument WORKSPACE_PATH leads to path traversal. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
A path traversal vulnerability has been identified in eghuzefa engineer-your-data versions through 0.1.3. The issue arises in the file operations functions within src/server.py, where the WORKSPACE_PATH variable is manipulated, allowing for arbitrary file access. This vulnerability can be exploited remotely, with a public exploit available.
It is recommended to enforce the WORKSPACE_PATH as a strict root for all file-related tools, ensuring that paths cannot escape the designated workspace. Additionally, running the application with a restricted user account that lacks access to sensitive files can help mitigate the risk.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 28, 2026CISA-ADP
Assessed Apr 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/eghuzefa/engineer-your-data-mcp/issues/1 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://vuldb.com/submit/802086 | [email protected] | Issue TrackingTechnical Description |
| https://vuldb.com/vuln/359814 | [email protected] | AdvisoryExploitTechnical Description |
| https://vuldb.com/vuln/359814/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| eghuzefa engineer-your-data | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 28, 2026 | New CVE Received | [email protected] |
Volerion