Junglewise Threat Intelligence

CVE-2026-81486: bsmi021 mcp-file-context-server path traversal in read_context

CVE-2026-81486 · Severity: medium · CVSS 5.3 · Published 2026-08-27

Executive brief

bsmi021 mcp-file-context-server is a tool that allows large language models (LLMs) to read and analyze files from a server's filesystem. A path traversal vulnerability in the read_context function allows attackers to read arbitrary files outside the intended project directory, such as system configuration files or sensitive data, if they can invoke the MCP tool.

Technical details

The vulnerability is a classic path traversal (CWE-22) in the read_context function of src/index.ts. The vulnerable code resolves user-supplied file paths using path.resolve(process.cwd(), filePath) without enforcing that the final resolved path remains within a configured workspace or allowed root directory. An attacker can supply sequences like "../../../../etc/passwd" to escape the intended context and read arbitrary files accessible to the server process. The attack requires ability to invoke the MCP tool interface (network-reachable if exposed), but requires no authentication or user interaction. Manual reproduction has been confirmed; no patch is available as of the report date.

Affected products

  • bsmi021 mcp-file-context-server 1.0.0

Timeline

  • 2026-08-27: disclosed: CVE-2026-81486 published
  • 2026-07-08: other: Vulnerability reported to vendor via GitHub issue; vendor has not responded
  • 2026-07-12: other: Issue #15 created on GitHub

References