What happened
NVD published CVE-2026-79534 on 2026-09-29. The reference mcp-filesystem-server's validatePath improperly resolves links on dangling symlinks, allowing traversal out of the configured allowed directories for filesystem write operations (unrated CVSS; advisory by TraceForce).
Why it matters
mcp-filesystem-server is the canonical filesystem-sandbox MCP server used to give LLM agents (coding agents, RAG pipelines) safe file access. A dangling-symlink traversal defeats the sandbox boundary — an agent (or an attacker steering one) can write/overwrite files anywhere on the host, e.g. drop config, SSH keys, or scripts outside the intended workspace root.
Attack vector
An attacker places a dangling symlink inside an allowed directory; when write_file/modify_file/copy_file/move_file/create_directory is called, filepath.EvalSymlinks returns os.IsNotExist, the fallback validates only the parent directory and returns the unresolved path, so the write follows the symlink and lands outside the sandbox root.
Affected systems
mark3labs mcp-filesystem-server v0.11.1 (validatePath, filesystemserver/handler/helper.go)
Mitigation
Upgrade mcp-filesystem-server beyond 0.11.1 and validate the fully-resolved (realpath) result against the allowed root for every link-resolved path; advisory: https://www.traceforce.ai/security-advisories/cve-2026-79534.