PT-2026-2278 · Unknown · Zen Mcp Server
CVE-2025-66689
·
Published
2026-01-12
·
Updated
2026-01-12
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zen MCP Server versions prior to 9.8.2
Description
A path traversal issue exists that allows authenticated attackers to read arbitrary files on the system. The issue is due to flawed logic in the
is dangerous path() validation function, which uses exact string matching against a blacklist of system directories. Attackers can bypass these restrictions by accessing subdirectories of blacklisted paths.Recommendations
Update Zen MCP Server to version 9.8.2 or later.
Exploit
Fix
Path traversal
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zen Mcp Server