A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of the argument skillName leads to path traversal. The attack can only be performed from a local environment. The project was informed of the problem early through an issue report but has not responded yet.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 09 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config.ts. Such manipulation of the argument skillName leads to path traversal. The attack can only be performed from a local environment. The project was informed of the problem early through an issue report but has not responded yet.
Title Jane-xiaoer skill-vision-control config.ts getSkillVersionsDir path traversal
First Time appeared Jane-xiaoer
Jane-xiaoer skill-vision-control
Weaknesses CWE-22
CPEs cpe:2.3:a:jane-xiaoer:skill-vision-control:*:*:*:*:*:*:*:*
Vendors & Products Jane-xiaoer
Jane-xiaoer skill-vision-control
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-13T19:37:18.682Z

Reserved: 2026-08-08T09:55:32.660Z

Link: CVE-2026-19335

cve-icon Vulnrichment

Updated: 2026-08-13T19:36:58.099Z

cve-icon NVD

Status : Deferred

Published: 2026-08-09T06:19:47.653

Modified: 2026-08-13T20:17:19.897

Link: CVE-2026-19335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T09:00:08Z

Weaknesses