CVE-2026-43901: Wireshark MCP server allows arbitrary export path via unsandboxed tool
Wireshark-MCP versions 1.1.5 and earlier expose a wireshark_export_objects MCP tool that passes an attacker-controlled dest_dir parameter to tshark's --export-objects flag without mandatory path restriction. Because the path sandbox is disabled unless WIRESHARK_MCP_ALLOWED_DIRS is set, a default installation permits exporting files to any directory on the filesystem.
Disclosed 11 May 2026 · Record updated 13 September 2026
Impact
An attacker able to invoke the MCP tool can direct tshark to write exported objects to any directory on the host filesystem in a default installation.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-43901
