Back

HIGH

@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality

Published Jan 7, 2026

Description

@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its "read_content" tool. This vulnerability arises from improper symlink handling in the path validation mechanism: the resolvePath function checks path validity before resolving symlinks, while fs.readFile resolves symlinks automatically during file access. This allows attackers to bypass directory restrictions by leveraging symlinks within the allowed directory that point to external files, enabling unauthorized access to files outside the intended operational scope.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 7, 2026
Updated Jan 7, 2026
Reserved Dec 8, 2025
CISA Vulnrichment
Updated Jan 7, 2026
NVD
Status Analyzed
Modified Sep 16, 2026
Red Hat
Severity n/a
Public date n/a