Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directories. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 02 Jul 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directories. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve. | |
Title | Model Context Protocol Servers Vulnerable to Path Validation Bypass via Prefix Matching and Symlink Handling | |
Weaknesses | CWE-59 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-02T14:30:57.647Z
Updated: 2025-07-02T14:50:18.562Z
Reserved: 2025-06-25T13:41:23.087Z
Link: CVE-2025-53109

Updated: 2025-07-02T14:50:12.316Z

Status : Awaiting Analysis
Published: 2025-07-02T15:15:27.670
Modified: 2025-07-03T15:13:53.147
Link: CVE-2025-53109

No data.