appium-mcp-server Path Traversal in File Write Tools
appium-mcp-server through version 0.1.61 fails to validate file paths in write_file and write_files_batch tools, allowing attackers to write files outside the intended directory and potentially overwrite arbitrary files with server privileges.
Disclosed 1 September 2026 · Record updated 13 September 2026
Impact
Attackers can overwrite arbitrary files including shell profiles and configuration files in the home directory using the server user's privileges.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-j4m2-645j-49qh
