All vulnerabilities CVE-2026-NONE · GHSA-x42w-fxc3-j24q troth: unauthenticated run_id path traversal in MCP tools leads to arbitrary-directory delete moderateCVSS 5.8CWE-22 Vendor xgre1 Package troth npm Affected <= 0.1.17 Fixed in 0.1.18 Disclosed 2026-08-30 Credit Avishai Gonen path-traversalmcparbitrary-delete Published advisory