HIGH
sylphxltd
CVE published 2026-01-07
CVE-2025-67366
CVE-2025-67366 is a high-severity path traversal vulnerability in the @sylphxltd/filesystem-mcp package. The vulnerability arises from improper symlink handling in the path validation mechanism, allowing attackers to bypass directory restrictions and access files outside the intended operational scope. This issue affects systems using the @sylphxltd/filesystem-mcp package, particularly those with unpatche [truncated]