CVE-2026-79534
Received Received - Intake

Directory Traversal in mark3labs mcp-filesystem-server

Vulnerability report for CVE-2026-79534, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: MITRE

Description

mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved path, so write_file (and modify_file, copy_file, move_file, create_directory) follows a pre-existing dangling symlink located inside an allowed directory and creates a file outside the configured allowed directories.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mark3labs mcp-filesystem-server 0.11.1
mark3labs mcp-filesystem-server From 0.11.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-79534 is a Directory Traversal vulnerability in mark3labs mcp-filesystem-server v0.11.1 caused by improper symlink handling in the validatePath function. When a dangling symlink (pointing to a non-existent target) is encountered, the function fails to fully resolve the path and instead validates only the parent directory. This allows write operations to follow the symlink and create files outside the intended allowed directories.

Detection Guidance

To detect this vulnerability, inspect the mcp-filesystem-server logs for write operations that create files outside allowed directories. Check for dangling symlinks in allowed directories pointing outside those directories. Use commands like 'find /allowed/dir -type l -xtype l' to locate dangling symlinks and 'ls -la /path/to/server/logs' to review file creation events.

Impact Analysis

An attacker could exploit this to write files outside the configured allowed directories, potentially leading to unauthorized file creation or modification. This could allow data exfiltration, system compromise, or disruption of services if critical files are overwritten. The impact is limited since existing files outside the allow-list remain blocked.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, violating compliance requirements for data protection such as GDPR (data integrity and confidentiality) and HIPAA (protected health information security). Organizations using this software may fail to meet regulatory obligations due to insufficient filesystem access controls.

Mitigation Strategies

Immediately restrict allowed directories to trusted locations and avoid granting write access to directories where untrusted parties can create symlinks. Monitor file creation operations closely and revoke write permissions from untrusted users. Patch the validatePath function to fully resolve intended paths in dangling-symlink cases before allowing write operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79534. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart