knowns path traversal vulnerabilities in MCP tool arguments
Multiple path traversal vulnerabilities in knowns before version 0.30.0 and through 0.33.0 allow attackers to read, create, overwrite and delete files outside the project directory via MCP tool arguments. AI agent sessions can bypass permission checks and access arbitrary files on the host system.
Disclosed 7 September 2026 · Record updated 13 September 2026
Impact
Attackers can read, create, overwrite and delete files outside the project directory, and bypass permission restrictions to gain unauthorized access to the file system.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-86439
- github.comhttps://github.com/advisories/GHSA-qjrq-cvv4-3g9w
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-88938
- github.comhttps://github.com/advisories/GHSA-qwj4-f78f-jj3j
- github.comhttps://github.com/advisories/GHSA-629c-j52g-h978
