Directory Traversal in mark3labs MCP Filesystem Server
CVE-2026-79534

5.9MEDIUM

Key Information:

Vendor

mark3labs

Vendor
CVE Published:
29 September 2026

What is CVE-2026-79534?

The MCP Filesystem Server v0.11.1 by mark3labs is susceptible to a directory traversal issue, specifically due to improper link resolution in its validatePath function. This vulnerability occurs when the system incorrectly processes dangling symlinks, allowing unauthorized file operations outside of the designated permitted directories. This exploitation could lead to potential breaches of sensitive data and unauthorized access, emphasizing the need for immediate remediation and enhancement of directory validation mechanisms.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.