Unintended File Access Risk in Model Context Protocol Servers by Model Context Protocol
CVE-2025-53109

7.3HIGH

Key Information:

Status
Vendor
CVE Published:
2 July 2025

What is CVE-2025-53109?

Model Context Protocol Servers are affected by a vulnerability that allows unintended access to files through symbolic links within permitted directories. This issue arises specifically in Filesystem versions before 0.6.4 and 2025.7.01. Users are strongly recommended to upgrade their installations to mitigate potential risks associated with unauthorized file access.

Affected Version(s)

servers < 0.6.4 < 0.6.4

servers < 2025.7.01 < 2025.7.01

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53109 : Unintended File Access Risk in Model Context Protocol Servers by Model Context Protocol