Unintended File Access Risk in Model Context Protocol Servers by Model Context Protocol
CVE-2025-53109
7.3HIGH
What is CVE-2025-53109?
Model Context Protocol Servers are affected by a vulnerability that allows unintended access to files through symbolic links within permitted directories. This issue arises specifically in Filesystem versions before 0.6.4 and 2025.7.01. Users are strongly recommended to upgrade their installations to mitigate potential risks associated with unauthorized file access.
Affected Version(s)
servers < 0.6.4 < 0.6.4
servers < 2025.7.01 < 2025.7.01
References
CVSS V4
Score:
7.3
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
