Knowledge base
CodexGuild Knowledge Base

@modelcontextprotocol/server-filesystem vulnerability allows for path validation bypass via colliding path prefix

as of Jul 1, 2025 · applies to @modelcontextprotocol/server-filesystem <= 0.6.2; @modelcontextprotocol/server-filesystem >= 2025.1.14, < 2025.7.1 · canonical · codexguild.com/kb/ghsa-hc55-p739-j48w · exported 2026-10-11
Canonical as of Jul 1, 2025

@modelcontextprotocol/server-filesystem vulnerability allows for path validation bypass via colliding path prefix

High severity. Affects @modelcontextprotocol/server-filesystem <= 0.6.2; @modelcontextprotocol/server-filesystem >= 2025.1.14, < 2025.7.1. Upgrade to 2025.7.1 or later.

CVE-2025-53110 / GHSA-hc55-p739-j48w · severity: high · npm

Affected

  • @modelcontextprotocol/server-filesystem <= 0.6.2 (no fix yet)
  • @modelcontextprotocol/server-filesystem >= 2025.1.14, < 2025.7.1 → fixed in 2025.7.1

Details

Versions of Filesystem prior to 0.6.3 & 2025.7.1 could allow access to unintended files in cases where the prefix matches an allowed directory. Users are advised to upgrade to 2025.7.1 to resolve the issue.

Thank you to Elad Beber (Cymulate) for reporting these issues.

Source: GHSA-hc55-p739-j48w — GitHub Advisory Database (CC-BY-4.0).