Executive brief
Wireshark-MCP is a tool that allows AI assistants to analyze network traffic data. A security flaw in this tool allows an attacker to trick the AI into writing files to any location on the computer's storage. This could allow an attacker to gain remote access to the system, modify critical configuration files, or disrupt operations.
Technical details
The wireshark-mcp library fails to enforce mandatory path restrictions on several file-writing operations, including 'wireshark_export_objects', 'merge_pcap_files', and various 'editcap' functions. The root cause is that the path sandbox (_allowed_dirs) defaults to None and only activates if the WIRESHARK_MCP_ALLOWED_DIRS environment variable is explicitly set. An attacker can exploit this via prompt injection against an AI model using the MCP server, or by providing a crafted pcap file with specific headers (e.g., Content-Disposition). This allows the attacker to write arbitrary content to sensitive locations like ~/.ssh/authorized_keys or /etc/cron.d/. As of the advisory date, no patch is available, but users can mitigate the risk by setting the WIRESHARK_MCP_ALLOWED_DIRS environment variable to a restricted directory.
Affected products
- bx33661 wireshark-mcp <= 1.1.5
Timeline
- 2026-04-25: disclosed: Initial disclosure in repository
- 2026-05-05: advisory: GitHub Advisory published
- 2026-05-11: other: NVD publication date