7.3
HIGH CVSS 4.0
CVE-2025-53109
Model Context Protocol Servers Vulnerable to Path Validation Bypass via Prefix Matching and Symlink Handling
Description

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directories. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve.

INFO

Published Date :

July 2, 2025, 3:15 p.m.

Last Modified :

April 15, 2026, 12:35 a.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2025-53109 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Lfprojects model_context_protocol_servers
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 4.0 HIGH [email protected]
Solution
Upgrade Filesystem to version 0.6.4 or 2025.7.01 to mitigate path traversal.
  • Upgrade Filesystem to version 0.6.4 or 2025.7.01.
Public PoC/Exploit Available at Github

CVE-2025-53109 has a 22 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2025-53109.

URL Resource
https://github.com/modelcontextprotocol/servers/commit/d00c60df9d74dba8a3bb13113f8904407cda594f
https://github.com/modelcontextprotocol/servers/security/advisories/GHSA-q66q-fx2p-7w4m
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-53109 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2025-53109 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

purplegate — Red/blue-team CI gate for agentic-AI apps. Prompt-injection, secrets, SAST, deps, IaC/RLS, workflow injection, MCP checks. One signed GitHub Action, mapped to OWASP LLM Top 10 v2025 + MITRE ATLAS.

agentic-ai ai-security ci-cd devsecops github-action llm-security mitre-atlas owasp owasp-llm-top-10 prompt-injection prompt-injection-detection sa sarif security supply-chain-security

Dockerfile Python

Updated: 5 hours, 5 minutes ago
0 stars 0 fork 0 watcher
Born at : April 24, 2026, 5 p.m. This repo has been linked 5 different CVEs too.

None

TypeScript JavaScript Shell Python

Updated: 1 week, 2 days ago
0 stars 0 fork 0 watcher
Born at : April 15, 2026, 12:04 p.m. This repo has been linked 5 different CVEs too.

None

TypeScript JavaScript Shell Python

Updated: 1 week, 5 days ago
0 stars 0 fork 0 watcher
Born at : April 12, 2026, 7:40 p.m. This repo has been linked 5 different CVEs too.

None

Shell Python

Updated: 1 week, 1 day ago
0 stars 0 fork 0 watcher
Born at : April 12, 2026, 2:21 p.m. This repo has been linked 2 different CVEs too.

High-performance, context-efficient filesystem MCP server built in Rust

HTML Rust

Updated: 2 weeks, 1 day ago
1 stars 0 fork 0 watcher
Born at : April 10, 2026, 1:06 a.m. This repo has been linked 2 different CVEs too.

None

TypeScript JavaScript Shell Python

Updated: 2 weeks, 2 days ago
0 stars 0 fork 0 watcher
Born at : April 8, 2026, 10:27 a.m. This repo has been linked 5 different CVEs too.

A curated timeline of real AI agent security incidents, breaches, and vulnerabilities (2024-2026). Every entry sourced and dated.

ai-agent-security ai-agents ai-security awesome-list cybersecurity llm-security mcp-security prompt-injection supply-chain-security adversarial-attacks agent-security agentic-ai ai-attacks ai-safety cve incident-response owasp red-team security-research vulnerability

Updated: 1 week ago
6 stars 1 fork 1 watcher
Born at : April 7, 2026, 2:19 p.m. This repo has been linked 46 different CVEs too.

An MCP server for Karpathy-style LLM wikis — deterministic, schema-blind, security-hardened.

Python

Updated: 2 weeks, 2 days ago
0 stars 0 fork 0 watcher
Born at : April 7, 2026, 9:11 a.m. This repo has been linked 1 different CVEs too.

Runtime security proxy for MCP servers — the open-source firewall between AI agents and tools

Dockerfile Go

Updated: 2 weeks, 6 days ago
0 stars 0 fork 0 watcher
Born at : April 4, 2026, 10:33 p.m. This repo has been linked 5 different CVEs too.

Supply-chain security for Claude Code plugins — detects marketplace auto-updates and surfaces security-relevant diffs

Python

Updated: 3 weeks ago
2 stars 1 fork 1 watcher
Born at : April 3, 2026, 1:44 a.m. This repo has been linked 5 different CVEs too.

None

CSS Python Shell PLpgSQL TypeScript

Updated: 1 month ago
0 stars 0 fork 0 watcher
Born at : March 24, 2026, 8:23 p.m. This repo has been linked 1 different CVEs too.

None

TypeScript JavaScript Shell Python

Updated: 1 month, 2 weeks ago
0 stars 0 fork 0 watcher
Born at : March 10, 2026, 10:59 p.m. This repo has been linked 5 different CVEs too.

Guía definitiva de Claude Code - Traducción al español latinoamericano

TypeScript JavaScript Shell Python

Updated: 1 month, 2 weeks ago
0 stars 0 fork 0 watcher
Born at : March 10, 2026, 1:57 p.m. This repo has been linked 5 different CVEs too.

Zero-dependency MCP security linter — 54 OWASP-mapped checks, 56 malicious packages, 28 CVEs. pip install mcp-config-guard

ai-safety claude-code linter mcp model-context-protocol owasp python sarif security vulnerability-scanner

Python

Updated: 1 month, 2 weeks ago
2 stars 0 fork 0 watcher
Born at : Feb. 28, 2026, 4 p.m. This repo has been linked 10 different CVEs too.

🤖 Team onboarding kit for Claude Code AI coding assistant. Pre-configured with agents, skills, slash commands, and MCP integrations for Java 21/Spring Boot WebFlux, Angular, Flutter, PostgreSQL, and Firebase. Clone → install → start building.

PLpgSQL Python Shell TypeScript CSS

Updated: 2 weeks, 6 days ago
20 stars 13 fork 13 watcher
Born at : Feb. 1, 2026, 11:32 p.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-53109 vulnerability anywhere in the article.

  • The Hacker News
5 Threats That Reshaped Web Security This Year [2025]

As 2025 draws to a close, security professionals face a sobering realization: the traditional playbook for web security has become dangerously obsolete. AI-powered attacks, evolving injection techniqu ... Read more

Published Date: Dec 04, 2025 (4 months, 2 weeks ago)
  • Kaspersky
Security risks of vibe coding and LLM assistants for developers

Although the benefits of AI assistants in the workplace remain debatable, where they’re being adopted most confidently of all is in software development. Here, LLMs play many roles — from refactoring ... Read more

Published Date: Oct 10, 2025 (6 months, 2 weeks ago)
  • Kaspersky
How LLMs can be compromised in 2025 | Kaspersky official blog

Developers of LLM-powered public services and business applications are working hard to ensure the security of their products, but the industry is still in its infancy. As a result, new types of attac ... Read more

Published Date: Sep 17, 2025 (7 months, 1 week ago)
  • The Hacker News
Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads

Cybersecurity researchers have discovered a critical vulnerability in the open-source mcp-remote project that could result in the execution of arbitrary operating system (OS) commands. The vulnerabili ... Read more

Published Date: Jul 10, 2025 (9 months, 2 weeks ago)
  • Daily CyberSecurity
Anthropic MCP Server Flaws: Path Traversal & Symlink Attacks Allow RCE

Image: Cymulate Cymulate Research Labs has revealed Anthropic’s Filesystem MCP Server vulnerabilities. Two newly disclosed flaws—CVE-2025-53110 and CVE-2025-53109—exposes systems to unauthorized acces ... Read more

Published Date: Jul 04, 2025 (9 months, 3 weeks ago)
  • Cyber Security News
Anthropic’s MCP Server Vulnerability Allowed Attackers to Escape Sandbox and Execute Code

Two high-severity vulnerabilities in Anthropic’s Model Context Protocol (MCP) Filesystem Server enable attackers to escape sandbox restrictions and execute arbitrary code on host systems. The vulnerab ... Read more

Published Date: Jul 03, 2025 (9 months, 3 weeks ago)

The following table lists the changes that have been made to the CVE-2025-53109 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by [email protected]

    Jul. 02, 2025

    Action Type Old Value New Value
    Added Description Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directories. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve.
    Added CVSS V4.0 AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-59
    Added Reference https://github.com/modelcontextprotocol/servers/commit/d00c60df9d74dba8a3bb13113f8904407cda594f
    Added Reference https://github.com/modelcontextprotocol/servers/security/advisories/GHSA-q66q-fx2p-7w4m
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.