Junglewise Threat Intelligence

CVE-2025-61685: Mastra Docs MCP Server directory traversal information disclosure

CVE-2025-61685 · Severity: low · CVSS 3.1 · Published 2025-09-24

Vendors: npm.

Executive brief

Mastra Docs MCP Server is a Node.js package that provides documentation context to AI coding assistants like Cursor IDE. The package contains a directory traversal vulnerability that allows attackers to bypass path validation checks and enumerate sensitive files and directories on a developer's local filesystem, such as cloud credentials, configuration files, and security tools, through prompt injection attacks.

Technical details

The vulnerability is a directory traversal (CWE-22) combined with information disclosure (CWE-200) in the @mastra/mcp-docs-server package versions ≤0.13.18. The readMdxContent function correctly checks if a resolved path stays within the intended base directory and returns early on failure. However, the execute function contains a logic flaw: it proceeds to call findNearestDirectory() and getMatchingPaths() even when readMdxContent returns false, and these functions do not perform path validation. An attacker can exploit this via prompt injection in an AI coding assistant, instructing it to request documentation for a traversal path like "../../../../../../../../". The vulnerable server then returns directory listings from arbitrary locations on the filesystem, exposing sensitive information. No authentication is required; the attack is facilitated through social engineering of the AI agent. The vulnerability was patched in version 0.17.0.

Affected products

  • Mastra @mastra/mcp-docs-server ≤0.13.18

Timeline

  • 2025-09-24: disclosed: GHSA-xh92-rqrq-227v published
  • 2025-09-24: patched: Version 0.17.0 released with fix

References