CVE Explorer
CVE-2025-67364
fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including fast_read_file. This vulnerability arises from improper path validation that fails to resolve symbolic links to their actual physical paths. The safePath and isPathAllowed functions use path.resolve() which does not handle symlinks, allowing attackers to bypass directory access restrictions by creating symlinks within allowed directories that point to restricted system paths.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-24","description":"CWE-24 Path Traversal: '../filedir'","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9f2e7044fcb5eb6e206d9143a4631a11823a23a1b3a962e1fd008f6b2fb59b81 · sha256:a2e8df0f6a2be392… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9f2e7044fcb5eb6e206d9143a4631a11823a23a1b3a962e1fd008f6b2fb59b81 · sha256:a2e8df0f6a2be392… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9f2e7044fcb5eb6e206d9143a4631a11823a23a1b3a962e1fd008f6b2fb59b81 · sha256:a2e8df0f6a2be392… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9f2e7044fcb5eb6e206d9143a4631a11823a23a1b3a962e1fd008f6b2fb59b81 · sha256:a2e8df0f6a2be392… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-24","description":"CWE-24 Path Traversal: '../filedir'","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9f2e7044fcb5eb6e206d9143a4631a11823a23a1b3a962e1fd008f6b2fb59b81 · sha256:a2e8df0f6a2be392… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9f2e7044fcb5eb6e206d9143a4631a11823a23a1b3a962e1fd008f6b2fb59b81 · sha256:a2e8df0f6a2be392… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://github.com/efforthye/fast-filesystem-mcp"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9f2e7044fcb5eb6e206d9143a4631a11823a23a1b3a962e1fd008f6b2fb59b81 · sha256:a2e8df0f6a2be392… · /containers/cna/references/1
{"url":"https://github.com/efforthye/fast-filesystem-mcp/issues/10"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9f2e7044fcb5eb6e206d9143a4631a11823a23a1b3a962e1fd008f6b2fb59b81 · sha256:a2e8df0f6a2be392… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.