Vulnerability  ·  2026-09-30

mark3labs mcp-filesystem-server symlink race lets agents write files outside their configured allowed directories

VulnerabilityMedium impactGlobalCVE-2026-79534
NVD published CVE-2026-79534 on 2026-09-29. The reference mcp-filesystem-server's validatePath improperly resolves links on dangling symlinks, allowing traversal out of the configured allowed directories for filesystem write operations (unrated CVSS; advisory by TraceForce).
mcp-filesystem-server is the canonical filesystem-sandbox MCP server used to give LLM agents (coding agents, RAG pipelines) safe file access. A dangling-symlink traversal defeats the sandbox boundary — an agent (or an attacker steering one) can write/overwrite files anywhere on the host, e.g. drop config, SSH keys, or scripts outside the intended workspace root.
An attacker places a dangling symlink inside an allowed directory; when write_file/modify_file/copy_file/move_file/create_directory is called, filepath.EvalSymlinks returns os.IsNotExist, the fallback validates only the parent directory and returns the unresolved path, so the write follows the symlink and lands outside the sandbox root.
mark3labs mcp-filesystem-server v0.11.1 (validatePath, filesystemserver/handler/helper.go)
Upgrade mcp-filesystem-server beyond 0.11.1 and validate the fully-resolved (realpath) result against the allowed root for every link-resolved path; advisory: https://www.traceforce.ai/security-advisories/cve-2026-79534.
NVD CVE-2026-79534TraceForce advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →