Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2025-67366: Path traversal via symlinks in @sylphxltd/filesystem-mcp v0.5.8

Version 0.5.8 of the @sylphxltd/filesystem-mcp MCP server contains a path traversal vulnerability in its read_content tool, where path validation occurs before symlink resolution. Attackers can use symlinks inside an allowed directory to read files outside the intended scope.

Disclosed 7 January 2026 · Record updated 13 September 2026

Impact

Unauthorised read access to files outside the MCP server's permitted directories, bypassing directory restrictions.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-67366