Vulnerability  ·  2026-07-25

BlenderMCP — Path Traversal in Polyhaven Asset Download via MITM/Prompt Injection

VulnerabilityMedium impactGlobalCVE-2026-66004
CVE-2026-66004 (CVSS 5.3, published July 24 2026) documents a path traversal vulnerability in BlenderMCP's asset-download tool that can be triggered via network MITM or prompt injection to achieve arbitrary file write.
This demonstrates the recurring pattern of MCP tool implementations trusting unsanitized external API response data, allowing a prompt-injection attack chain to translate into arbitrary file writes on the host running the AI agent's Blender integration — a niche but illustrative agentic tool-surface risk.
The download_polyhaven_asset method fails to sanitize traversal sequences in API response 'include' keys; an attacker performing a MITM attack or prompt injection can supply malicious paths to write arbitrary files to the host filesystem outside the intended download directory.
BlenderMCP (ahujasid/blender-mcp) before commit 30a3308446cd8f81a9446e5a2ed657c0d8d86072
Update to the patched commit 30a3308 or later.
VulnCheck Advisory: BlenderMCP Path Traversal
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →