
NVIDIA's RAG Blueprint had a path traversal in its MCP server. We got the fix merged in three days.
A CWE-22 path traversal in NVIDIA's RAG Blueprint MCP server allowed any MCP client to read arbitrary files and ingest them into the RAG collection. We submitted the fix and NVIDIA merged it.




















