PT-2025-27616 · Unknown · Filesystem
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Model Context Protocol Servers Filesystem versions prior to 0.6.4
Model Context Protocol Servers Filesystem versions prior to 2025.7.01
Description
An issue exists in the server-filesystem implementation of the Model Context Protocol (MCP) due to incorrect reference validation before file access. This flaw allows a remote attacker to gain unauthorized access to protected information by using symlinks (symbolic links, which are files that point to other files or directories) within allowed directories to access unintended files.
Recommendations
Update to version 0.6.4.
Update to version 2025.7.01.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filesystem