Junglewise Threat Intelligence

CVE-2026-7213: ef10007 MLOps_MCP path traversal in save_file tool

CVE-2026-7213 · Severity: high · CVSS 7.3 · Published 2026-04-28

Executive brief

A vulnerability exists in MLOps_MCP, a tool used for managing machine learning operations. An attacker can exploit this flaw to access or overwrite sensitive files on the server by manipulating file paths. This could lead to the exposure of private data or the disruption of machine learning services.

Technical details

A path traversal vulnerability (CWE-22) was identified in the 'save_file' tool component of ef10007 MLOps_MCP version 1.0.0. The flaw resides in the fastmcp_server.py file, where insufficient validation of the 'filename' and 'destination' arguments allows for directory traversal. A remote, unauthenticated attacker can exploit this to read or write files outside of the restricted directory. While the project was notified via a GitHub issue, no official patch has been released at this time, and a public exploit is reportedly available.

Affected products

  • ef10007 MLOps_MCP 1.0.0

Timeline

  • 2026-04-27: disclosed: Vulnerability reported to project via GitHub issue
  • 2026-04-28: advisory: NVD publication date

References