Junglewise Threat Intelligence

mcp-ssh-tool file transfer path policy bypass and bearer token timing vulnerability

Severity: high · CVSS 8.7 · Published 2026-05-07

Vendors: npm.

Executive brief

mcp-ssh-tool is a utility for managing remote file transfers and SSH operations. The tool contains two security flaws: insufficient validation of file transfer paths that could allow an attacker to bypass access restrictions and read/write unauthorized files, and a timing-based weakness in HTTP bearer token authentication that could leak credential information. These vulnerabilities affect all versions prior to 2.1.1.

Technical details

The vulnerability comprises two distinct flaws: (1) Path traversal due to CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) in file transfer operations, caused by insufficient local path policy enforcement and incomplete canonicalization/segment-boundary handling for deny-prefix path policy checks, allowing bypass of configured access restrictions; and (2) Timing side-channel due to CWE-208 (Observable Timing Discrepancy) in HTTP bearer token comparison, using non-constant-time string comparison that leaks information about valid authentication tokens. The path policy bypass affects transfer-related filesystem handling under specific configurations. The bearer token timing vulnerability is relevant only in HTTP deployments. Both require no privileges or user interaction, attack complexity is low, and network-based exploitation is possible. Patch available in version 2.1.1 and later.

Affected products

  • mcp-ssh-tool mcp-ssh-tool <= 2.1.0

Timeline

  • 2026-05-07: disclosed: Advisory published to GitHub Advisory Database
  • 2026-05-07: patched: Patched version 2.1.1 released

References

Related threats