CVE-2026-79534 Details
Description
mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved path, so write_file (and modify_file, copy_file, move_file, create_directory) follows a pre-existing dangling symlink located inside an allowed directory and creates a file outside the configured allowed directories.
A directory traversal vulnerability has been identified in mark3labs mcp-filesystem-server version 0.11.1. The issue arises from improper link resolution in the validatePath function, which allows the write_file, modify_file, copy_file, move_file, and create_directory functions to follow dangling symlinks from allowed directories to create files outside the permitted areas.
Mark3labs mcp-filesystem-server has not yet released a patch for this vulnerability. However, server operators are advised to keep allowed directories limited to trusted locations and avoid granting write permissions in directories that could be manipulated with symlinks by untrusted parties.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.traceforce.ai/security-advisories/cve-2026-79534 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mark3labs mcp-filesystem-server | v0.11.1 (semver) main commit ba3f07f |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion