Junglewise Threat Intelligence

CVE-2026-7315: eiceblue spire-pdf-mcp-server path traversal in get_pdf_path

CVE-2026-7315 · Severity: high · CVSS 7.3 · Published 2026-04-28

Executive brief

eiceblue spire-pdf-mcp-server is a tool used to manage and convert PDF documents. A security flaw allows remote attackers to bypass directory restrictions and access or create files anywhere on the host system that the server has permission to reach. This could lead to the theft of sensitive documents or the unauthorized modification of system files.

Technical details

A path traversal vulnerability exists in the get_pdf_path function within src/spire_pdf_mcp/server.py of eiceblue spire-pdf-mcp-server 0.1.1. The root cause is the improper validation of the 'filepath' argument, which fails to normalize paths or check for directory boundaries, allowing absolute paths and traversal sequences (e.g., '../'). An unauthenticated remote attacker can exploit this by sending crafted MCP tool calls to functions like create_pdfdocument or convert_pdfdocument. This enables arbitrary file reads of existing PDFs and arbitrary file writes to any location writable by the service account. As of the advisory date, no official patch has been released.

Affected products

  • eiceblue spire-pdf-mcp-server 0.1.1

Timeline

  • 2026-04-10: disclosed: Vulnerability reported to vendor via GitHub issue
  • 2026-04-28: advisory: Initial disclosure via VulDB and NVD

References