CVE-2026-8116 Details
Description
A weakness has been identified in huangjunsen0406 xiaozhi-mcphub up to 1.0.3. This vulnerability affects unknown code of the file src/controllers/dxtController.ts. This manipulation of the argument manifest.name causes path traversal. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
A path traversal vulnerability has been identified in Huangjunsen0406 Xiaozhi-Mcphub versions through 1.0.3. The issue arises in the DXT upload handler, specifically within the 'src/controllers/dxtController.ts' file. The vulnerability allows an attacker to manipulate the 'manifest.name' value in the uploaded DXT file, causing extracted files to be placed outside the intended directory. This issue can be exploited remotely, and the vulnerability has been publicly disclosed.
It is recommended to sanitize the 'manifest.name' value before using it in file paths, ensuring it does not contain traversal sequences or absolute path indicators. Additionally, the upload directory should be monitored and managed to prevent unauthorized access or exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 8, 2026CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/huangjunsen0406/xiaozhi-mcphub/ | [email protected] | ProductVendor |
| https://github.com/huangjunsen0406/xiaozhi-mcphub/issues/29 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/submit/808260 | [email protected] | Permission Required |
| https://vuldb.com/vuln/361904 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/361904/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| huangjunsen0406 xiaozhi-mcphub | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | New CVE Received | [email protected] |
Volerion