Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dexhunter
Dexhunter kaggle-mcp |
|
| Vendors & Products |
Dexhunter
Dexhunter kaggle-mcp |
Mon, 27 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerability affects the function prepare_kaggle_dataset of the file src/kaggle_mcp/server.py. The manipulation of the argument competition_id leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | dexhunter kaggle-mcp server.py prepare_kaggle_dataset path traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-27T19:29:54.456Z
Reserved: 2026-04-26T20:02:16.564Z
Link: CVE-2026-7149
Updated: 2026-04-27T19:29:45.823Z
Status : Deferred
Published: 2026-04-27T19:16:54.277
Modified: 2026-04-27T19:25:04.600
Link: CVE-2026-7149
No data.
OpenCVE Enrichment
Updated: 2026-04-28T09:16:57Z