CVE-2026-7217
A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read_docx/read_xlsx/read_pptx/list_xlsx_sheets/read_pdf of the file packages/mcp-office/src/index.ts of the component Document File Handler. Such manipulation of the argument path leads to absolute path traversal. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.44%
- CWE
- CWE-36, CWE-22
- Published
- 2026-04-28
- Last modified
- 2026-04-28
Affected products
- Deepractice PromptX
- Deepractice PromptX
- Deepractice PromptX
- Deepractice PromptX
- Deepractice PromptX
Weakness type
Related vulnerabilities
- CVE-2026-68896 — Microsoft Windows Search Component Elevation of Privilege Vulnerability
- CVE-2026-69612 — Windows Error Reporting Elevation of Privilege Vulnerability
- CVE-2026-47630 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an...
- CVE-2026-47606 — NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an...
- CVE-2026-46345 — compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
- CVE-2026-47243 — Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
- CVE-2026-54202 — TeamDavid: Path Traversal in the archive creation functionality
- CVE-2026-61891 — In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP...