PatchSiren

sylphxltd CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH sylphxltd CVE published 2026-01-07

CVE-2025-67366

CVE-2025-67366 is a high-severity path traversal vulnerability in the @sylphxltd/filesystem-mcp package. The vulnerability arises from improper symlink handling in the path validation mechanism, allowing attackers to bypass directory restrictions and access files outside the intended operational scope. This issue affects systems using the @sylphxltd/filesystem-mcp package, particularly those with unpatche [truncated]