CVE-2025-67366 (CNNVD-202601-1195)
中文标题:
Filesystem MCP 安全漏洞
英文标题:
@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. ...
漏洞描述
中文描述:
Filesystem MCP是Sylphx开源的一个MCP文件系统服务器。 Filesystem MCP 0.5.8版本存在安全漏洞,该漏洞源于路径验证机制中符号链接处理不当,可能导致绕过目录限制,访问未授权文件。
英文描述:
@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its "read_content" tool. This vulnerability arises from improper symlink handling in the path validation mechanism: the resolvePath function checks path validity before resolving symlinks, while fs.readFile resolves symlinks automatically during file access. This allows attackers to bypass directory restrictions by leveraging symlinks within the allowed directory that point to external files, enabling unauthorized access to files outside the intended operational scope.
CWE类型:
标签:
受影响产品
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (adp)
HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-67366 |
2026-01-08 02:08:10 | 2026-01-12 02:12:26 |
| NVD | nvd_CVE-2025-67366 |
2026-01-09 03:00:09 | 2026-01-12 02:28:05 |
| CNNVD | cnnvd_CNNVD-202601-1195 |
2026-01-11 06:15:11 | 2026-01-12 02:38:12 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202601-1195
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']