PT-2026-96003 · Ace-Mcp · Ace-Mcp
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
0215AndrewFeng ACE-MCP versions prior to 4.10.9
Description
A path traversal issue exists in the MCP Tool component within the
get file snippet() function of the getFileSnippet.ts file. This flaw allows a remote attacker to access files outside the intended directory by manipulating the projectRootPath and filePath arguments. The issue occurs because the isPathInsideProjectRoot validation only prevents the filePath from escaping the projectRootPath, but it does not validate the projectRootPath itself, which is provided as untrusted client input.Recommendations
As a temporary workaround, restrict or avoid using the
projectRootPath and filePath arguments in the get file snippet() function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ace-Mcp