CVE-2025-53109

Source
https://cve.org/CVERecord?id=CVE-2025-53109
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53109.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-53109
Aliases
Published
2025-07-02T14:30:57.647Z
Modified
2026-04-10T05:30:34.815870Z
Severity
  • 7.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
Model Context Protocol Servers Vulnerable to Path Validation Bypass via Prefix Matching and Symlink Handling
Details

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directories. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-59"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53109.json"
}
References

Affected packages

Git / github.com/modelcontextprotocol/servers

Affected ranges

Type
GIT
Repo
https://github.com/modelcontextprotocol/servers
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*
0.1.0
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.5.1
python-servers-0.*
python-servers-0.6.1
python-servers-0.6.2
typescript-servers-0.*
typescript-servers-0.6.0
typescript-servers-0.6.1
typescript-servers-0.6.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53109.json"