VYPR

mcp-filesystem-server

by Mark3labs

CVEs (1)

  • CVE-2026-79534Sep 29, 2026
    risk 0.00cvss —epss —

    mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent…