Executive brief
grok-faf-mcp is an MCP server that manages persistent project context for AI agents and development tools. An unauthenticated attacker can exploit path traversal to read any file accessible to the server process, including SSH keys, cloud credentials, and environment files. The vulnerability can be triggered by prompt injection of malicious tool calls into LLM processing of attacker-controlled content.
Technical details
The vulnerability is a path traversal (CWE-22) and external control of file name/path (CWE-73) issue in multiple MCP tools including refresh_faf, faf_score, faf_get_orchestration_policy, refresh_blend, and general-purpose faf_read/faf_write tools. These tools accept caller-controlled path arguments, expand tildes, and resolve them using path.resolve() without confining the result to a trusted project directory. Absolute paths and ../ traversals are processed as-is, allowing reads outside the intended .faf project context. Attack vector is local/stdio-based; an MCP client or LLM receiving prompt-injected tool calls can trigger arbitrary file reads. The server echoes file contents verbatim in some cases (refresh_faf) or reflects parsed values and resolved paths (faf_get_orchestration_policy). The vulnerability was patched in version 1.5.3 by canonicalizing paths through symlinks and rejecting absolute paths and traversal attempts, restricting access to .faf/.fafm context files and project root.
Affected products
- Wolfe-Jam grok-faf-mcp <= 1.5.2
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fixed in version 1.5.3