Executive brief
A security flaw was found in augments-mcp-server, a tool used to provide framework documentation to AI assistants like Claude. An attacker can trick the server into reading sensitive files from the host computer by providing a manipulated file path. This could lead to the exposure of private configuration files, credentials, or system information.
Technical details
A path traversal vulnerability exists in the `scanProjectDeps` function within `src/tools/v4/scan-project-deps.ts`. The `packageJsonPath` argument is passed directly to `fs.readFile()` without path sanitization or confinement to a project root. An attacker can use absolute paths or '..' segments to read any file accessible to the server process. If the file is valid JSON, its contents are parsed and returned; if it is not JSON, a fragment of the file content is leaked through the resulting SyntaxError message. Additionally, keys from successfully parsed JSON files are exfiltrated to the public npm registry during dependency lookups.
Affected products
- augmnt augments-mcp-server 7.1.0
Timeline
- 2026-07-13: advisory: NVD publication date
- 2026-07-13: disclosed: Public issue report on GitHub