Path traversal in Zen MCP Server allows arbitrary file reads (CVE-2025-66689)
CVE-2025-66689 describes a path traversal flaw in Zen MCP Server before version 9.8.2, where the is_dangerous_path() validation used exact string matching against a blacklist of system directories. Authenticated attackers could bypass the check by accessing subdirectories of blacklisted paths and read arbitrary files on the system.
Disclosed 12 January 2026 · Record updated 13 September 2026
Impact
Authenticated attackers could read arbitrary files on the host system running the MCP server; fixed in version 9.8.2.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-66689
