PT-2025-27616 · Unknown · Filesystem

·

CVE-2025-53109

·

Published

2025-07-01

·

Updated

2026-07-20

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Model Context Protocol Servers Filesystem versions prior to 0.6.4 Model Context Protocol Servers Filesystem versions prior to 2025.7.01
Description An issue exists in the server-filesystem implementation of the Model Context Protocol (MCP) due to incorrect reference validation before file access. This flaw allows a remote attacker to gain unauthorized access to protected information by using symlinks (symbolic links, which are files that point to other files or directories) within allowed directories to access unintended files.
Recommendations Update to version 0.6.4. Update to version 2025.7.01.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09365
CVE-2025-53109
GHSA-Q66Q-FX2P-7W4M

Affected Products

Filesystem