PT-2026-2278 · Unknown · Zen Mcp Server

CVE-2025-66689

·

Published

2026-01-12

·

Updated

2026-01-12

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zen MCP Server versions prior to 9.8.2
Description A path traversal issue exists that allows authenticated attackers to read arbitrary files on the system. The issue is due to flawed logic in the is dangerous path() validation function, which uses exact string matching against a blacklist of system directories. Attackers can bypass these restrictions by accessing subdirectories of blacklisted paths.
Recommendations Update Zen MCP Server to version 9.8.2 or later.

Exploit

Fix

Path traversal

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66689

Affected Products

Zen Mcp Server