CyberRota Analysis
AI-GeneratedVersions prior to 0.30.0 of the MCP tool are vulnerable due to inadequate validation of filesystem paths in command arguments, enabling attackers to exploit directory traversal sequences. This flaw allows unauthorized file access, including reading, creating, overwriting, and deleting files outside the designated project directory. Organizations using affected versions should prioritize patching to mitigate the risk of data exposure and potential system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server process.