Path Traversal Vulnerability in Appium MCP Server by Argneshu
CVE-2026-84201

6.9MEDIUM

Key Information:

Vendor

Argneshu

Vendor
CVE Published:
1 September 2026

What is CVE-2026-84201?

The Appium MCP Server up to version 0.1.61 exposes a critical vulnerability that fails to properly validate or normalize file paths within its write_file and write_files_batch functions. This oversight enables malicious actors to exploit the server's file management capabilities by supplying crafted absolute or relative file paths, potentially allowing unauthorized access to sensitive areas outside the designated PROJECT_ROOT directory. As a result, attackers can overwrite crucial files, including configuration files and shell profiles, with the privileges of the server user, which could lead to severe security compromises.

Affected Version(s)

appium-mcp-server 0 <= 0.1.61

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mil4n
.