7.3
HIGH CVSS 4.0
CVE-2025-53109
Model Context Protocol Servers Vulnerable to Path Validation Bypass via Prefix Matching and Symlink Handling
Description

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directories. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve.

INFO

Published Date :

July 2, 2025, 3:15 p.m.

Last Modified :

July 3, 2025, 3:13 p.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2025-53109 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 4.0 HIGH [email protected]
Solution
Upgrade Filesystem to version 0.6.4 or 2025.7.01 to mitigate path traversal.
  • Upgrade Filesystem to version 0.6.4 or 2025.7.01.
Public PoC/Exploit Available at Github

CVE-2025-53109 has a 10 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2025-53109.

URL Resource
https://github.com/modelcontextprotocol/servers/commit/d00c60df9d74dba8a3bb13113f8904407cda594f
https://github.com/modelcontextprotocol/servers/security/advisories/GHSA-q66q-fx2p-7w4m
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-53109 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2025-53109 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Guía definitiva de Claude Code - Traducción al español latinoamericano

TypeScript JavaScript Shell Python

Updated: 6 hours, 5 minutes ago
0 stars 0 fork 0 watcher
Born at : March 10, 2026, 1:57 p.m. This repo has been linked 5 different CVEs too.

Zero-dependency MCP security linter — 54 OWASP-mapped checks, 56 malicious packages, 28 CVEs. pip install mcp-config-guard

ai-safety claude-code linter mcp model-context-protocol owasp python sarif security vulnerability-scanner

Python

Updated: 2 days, 16 hours ago
2 stars 0 fork 0 watcher
Born at : Feb. 28, 2026, 4 p.m. This repo has been linked 10 different CVEs too.

🤖 Team onboarding kit for Claude Code AI coding assistant. Pre-configured with agents, skills, slash commands, and MCP integrations for Java 21/Spring Boot WebFlux, Angular, Flutter, PostgreSQL, and Firebase. Clone → install → start building.

PLpgSQL Python Shell

Updated: 1 day, 16 hours ago
7 stars 7 fork 7 watcher
Born at : Feb. 1, 2026, 11:32 p.m. This repo has been linked 1 different CVEs too.

Educational/Research companion: Security vulnerabilities in AI coding assistants (Claude, Cursor, Copilot) - CVEs, supply chain attacks, trust boundaries

Dockerfile Shell Jupyter Notebook Python

Updated: 2 months ago
0 stars 0 fork 0 watcher
Born at : Jan. 10, 2026, 5:48 a.m. This repo has been linked 8 different CVEs too.

A tremendous feat of documentation, this guide covers Claude Code from beginner to power user, with production-ready templates for Claude Code features, guides on agentic workflows, and a lot of great learning materials, including quizzes and a handy "cheatsheet". Whether it's the "ultimate" guide to Claude Code will be up to the reader :)

agentic-coding ai-assistant ai-coding ai-pair-programming anthropic best-practices claude claude-code cli-tool coding-assistant developer-tools llm mcp-servers tutorial ai-security claude-code-guide cursor-alternative prompt-engineering vibe-coding claude-code-tutorial

JavaScript Shell Python TypeScript

Updated: 21 hours, 35 minutes ago
1111 stars 172 fork 172 watcher
Born at : Jan. 9, 2026, 1:42 p.m. This repo has been linked 5 different CVEs too.

Real-time security layer protecting AI Agents from Confused Deputy attacks, malicious MCP payloads, and Indirect Prompt Injection.

ai rag-pipeline security mcp-client mcp agentic-ai ai-security firewall llm-security mcp-security model-context-protocol prompt-injection rug-pull tool-poisoning

Python YARA

Updated: 1 day, 9 hours ago
4 stars 0 fork 0 watcher
Born at : Jan. 3, 2026, 9:50 a.m. This repo has been linked 7 different CVEs too.

A Security-centric MCP Server providing enterprise-grade filesystem powers to AI assistants—read, write, edit, and manage files with comprehensive CVE protection and user-controlled access.. [Explore comprehensive code documentation and architecture details on DeepWiki](https://deepwiki.com/n0zer0d4y/vulcan-file-ops)

batch-operations code-analysis code-generation filesystem shell-execution vibe-coding dynamic-directory-access secure-mcp selective-tool-activation mcp-server model-context-protocol docx-generation pdf-generation developer-tools

JavaScript TypeScript Dockerfile

Updated: 1 week, 5 days ago
9 stars 2 fork 2 watcher
Born at : Oct. 9, 2025, 4:48 a.m. This repo has been linked 4 different CVEs too.

None

Updated: 6 months, 3 weeks ago
1 stars 0 fork 0 watcher
Born at : Aug. 11, 2025, 12:21 a.m. This repo has been linked 4 different CVEs too.

MCP Guardian Enterprise is an advanced security platform for MCP servers, powered by Naptha AI’s autonomous agent framework. It delivers comprehensive, scalable vulnerability scanning, threat intelligence, and automated remediation. The modular architecture covers runtime, network, secrets, IaC, compliance, and more for enterprise-grade protection.

JavaScript HTML

Updated: 6 months, 1 week ago
0 stars 0 fork 0 watcher
Born at : July 25, 2025, 9:03 p.m. This repo has been linked 5 different CVEs too.

A collection of Vulnerability Research and Reverse Engineering writeups.

Updated: 2 months, 2 weeks ago
5 stars 0 fork 0 watcher
Born at : Dec. 21, 2024, 2:55 p.m. This repo has been linked 151 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-53109 vulnerability anywhere in the article.

  • The Hacker News
5 Threats That Reshaped Web Security This Year [2025]

As 2025 draws to a close, security professionals face a sobering realization: the traditional playbook for web security has become dangerously obsolete. AI-powered attacks, evolving injection techniqu ... Read more

Published Date: Dec 04, 2025 (3 months ago)
  • Kaspersky
Security risks of vibe coding and LLM assistants for developers

Although the benefits of AI assistants in the workplace remain debatable, where they’re being adopted most confidently of all is in software development. Here, LLMs play many roles — from refactoring ... Read more

Published Date: Oct 10, 2025 (5 months ago)
  • Kaspersky
How LLMs can be compromised in 2025 | Kaspersky official blog

Developers of LLM-powered public services and business applications are working hard to ensure the security of their products, but the industry is still in its infancy. As a result, new types of attac ... Read more

Published Date: Sep 17, 2025 (5 months, 3 weeks ago)
  • The Hacker News
Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads

Cybersecurity researchers have discovered a critical vulnerability in the open-source mcp-remote project that could result in the execution of arbitrary operating system (OS) commands. The vulnerabili ... Read more

Published Date: Jul 10, 2025 (8 months ago)
  • Daily CyberSecurity
Anthropic MCP Server Flaws: Path Traversal & Symlink Attacks Allow RCE

Image: Cymulate Cymulate Research Labs has revealed Anthropic’s Filesystem MCP Server vulnerabilities. Two newly disclosed flaws—CVE-2025-53110 and CVE-2025-53109—exposes systems to unauthorized acces ... Read more

Published Date: Jul 04, 2025 (8 months ago)
  • Cyber Security News
Anthropic’s MCP Server Vulnerability Allowed Attackers to Escape Sandbox and Execute Code

Two high-severity vulnerabilities in Anthropic’s Model Context Protocol (MCP) Filesystem Server enable attackers to escape sandbox restrictions and execute arbitrary code on host systems. The vulnerab ... Read more

Published Date: Jul 03, 2025 (8 months, 1 week ago)

The following table lists the changes that have been made to the CVE-2025-53109 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by [email protected]

    Jul. 02, 2025

    Action Type Old Value New Value
    Added Description Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directories. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve.
    Added CVSS V4.0 AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-59
    Added Reference https://github.com/modelcontextprotocol/servers/commit/d00c60df9d74dba8a3bb13113f8904407cda594f
    Added Reference https://github.com/modelcontextprotocol/servers/security/advisories/GHSA-q66q-fx2p-7w4m
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
Vulnerability Scoring Details
Base CVSS Score: 7.3
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability