Executive brief
houtini-lm is an MCP server that delegates code tasks to local or cloud language models. A path traversal vulnerability in the code_task_files component allows remote attackers to read arbitrary files from the server by manipulating file paths, potentially exposing sensitive configuration, source code, or other confidential data stored on the system.
Technical details
The vulnerability is a path traversal flaw in an unknown function within src/index.ts of the code_task_files component in houtini-lm up to version 2.13.2. The vulnerability allows remote manipulation of file paths without proper validation, enabling an attacker to traverse the filesystem and access files outside intended boundaries. The fix was applied in commit 35d97bca0531894da36a85aedb95312da1bd5b7a, which implements readGuardedFile() with per-file size caps (HOUTINI_LM_MAX_FILE_MB, default 10 MB) and optional root confinement via HOUTINI_LM_FILE_ROOTS after symlink resolution. No authentication is required for exploitation since the attack can be launched remotely.
Affected products
- houtini-ai houtini-lm up to 2.13.2
Timeline
- 2026-08-28: disclosed
- 2026-08-28: patched: Patch commit 35d97bca0531894da36a85aedb95312da1bd5b7a