A vulnerability labeled as critical has been found in ahujasid blender-mcp . The affected element is the function download_polyhaven_asset . The manipulation results in path traversal. This vulnerability was named CVE-2026-66004 . The attack may be performed from remote. There is no available exploit. A patch should be applied to remediate this issue.