CVE-2026-79534

mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved path, so write_file (and modify_file, copy_file, move_file, create_directory) follows a pre-existing dangling symlink located inside an allowed directory and creates a file outside the configured allowed directories.

  • Published Sep 29, 2026
  • CVSS 5.9 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

CVE-2026-79534 at the National Vulnerability Database