Executive brief
with-context-mcp is a Model Context Protocol server that manages notes and file synchronization across projects and vaults. A path traversal vulnerability in the note ingest, sync, and teleport functions allows remote attackers to read, write, or delete arbitrary files on the system outside the intended project boundaries, potentially compromising sensitive data and system integrity.
Technical details
The vulnerability is a path traversal flaw (CWE-22) in the note ingestion, synchronization, and teleportation tools within src/index.ts and related tool files. The affected functions (ingest_notes, sync_notes, teleport_notes) accept caller-influenced project_folder and file path parameters that are not properly validated or canonicalized before being used in filesystem operations (readFile, writeFile, unlink). An unauthenticated remote attacker can invoke the MCP endpoint with directory traversal sequences (e.g., "../outside-project") to read, write, or delete files outside the intended project/vault directory. The vulnerability has no known patch as of the report date, and manual reproduction has been confirmed.
Affected products
- boxpositron with-context-mcp up to 3.0.7
Timeline
- 2026-07-12: disclosed: Vulnerability report opened on GitHub
- 2026-08-27: advisory: CVE-2026-81491 assigned and published