Junglewise Threat Intelligence

CVE-2026-14699: zcaceres markdownify-mcp symlink following in assertPathAllowed

CVE-2026-14699 · Severity: low · CVSS 3.3 · Published 2026-07-05

Executive brief

markdownify-mcp is a tool used to convert various file formats into Markdown. A security flaw allows a local user to bypass directory restrictions by using symbolic links (shortcuts). This could allow an attacker to read sensitive files on the system that the tool was intended to keep private, provided they already have local access to the machine.

Technical details

A symbolic link (symlink) following vulnerability exists in the `assertPathAllowed` function within `src/Markdownify.ts` (and `src/utils.ts`). The application performs lexical path validation using `startsWith()` on normalized strings rather than canonicalizing paths using `realpath`. A local attacker can create a symlink within an allowed directory that points to a file outside of the restricted boundary. When the application processes the symlink, it validates the path based on its appearance within the allowlist but subsequently reads the target file outside the intended directory. This bypasses `MD_ALLOWED_PATHS` and `MD_SHARE_DIR` configurations. A fix involving `realpath` and `path.relative` has been proposed in pull request #109.

Affected products

  • zcaceres markdownify-mcp up to 1.1.0

Timeline

  • 2026-06-03: disclosed: Issue reported on GitHub
  • 2026-06-03: other: Fix proposed via pull request #109
  • 2026-07-05: advisory: CVE published and NVD record created

References

Related threats