{"id":"GHSA-hc55-p739-j48w","summary":"@modelcontextprotocol/server-filesystem vulnerability allows for path validation bypass via colliding path prefix","details":"Versions of Filesystem prior to 0.6.3 & 2025.7.1 could allow access to unintended files in cases where the prefix matches an allowed directory. Users are advised to upgrade to 2025.7.1 to resolve the issue.\n\nThank you to Elad Beber (Cymulate) for reporting these issues.","aliases":["CVE-2025-53110"],"modified":"2025-07-02T18:57:22Z","published":"2025-07-01T20:14:00Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-07-01T20:14:00Z","nvd_published_at":"2025-07-02T15:15:27Z","cwe_ids":["CWE-22"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/servers/security/advisories/GHSA-hc55-p739-j48w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53110"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/servers/commit/cc99bdabdcad93a58877c5f3ab20e21d4394423d"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/servers"}],"affected":[{"package":{"name":"@modelcontextprotocol/server-filesystem","ecosystem":"npm","purl":"pkg:npm/%40modelcontextprotocol/server-filesystem"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.6.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-hc55-p739-j48w/GHSA-hc55-p739-j48w.json"}},{"package":{"name":"@modelcontextprotocol/server-filesystem","ecosystem":"npm","purl":"pkg:npm/%40modelcontextprotocol/server-filesystem"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2025.1.14"},{"fixed":"2025.7.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-hc55-p739-j48w/GHSA-hc55-p739-j48w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:H/SI:H/SA:H"}]}