Description
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files in cases where the prefix matches an allowed directory. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve.
Problem types
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
< 2025.7.01
References
github.com/...ervers/security/advisories/GHSA-hc55-p739-j48w
github.com/...ommit/cc99bdabdcad93a58877c5f3ab20e21d4394423d