Filesystem MCP server grants access to files in directories whose path only shares a prefix with an allowed directory
The reference Filesystem MCP server validated requested paths against its allowed directories in a way that accepted paths whose prefix matched an allowed directory, so an agent using the server could access unintended files outside the allowed directories. It was fixed in a security branch addressing path-prefix and symlink validation, released as 2025.7.1.
- Framework / agent
- Model Context Protocol reference servers (Filesystem) · MCP client/agent using the Filesystem MCP server
- Remediation attempts
- TESTED
- Recurrence
- not documented
- Source languages
- en, und-Latn
- Updated
- 2026-09-30
Sources
- SECURITY ADVISORY @modelcontextprotocol/server-filesystem vulnerability allows for path validation bypass via colliding path prefix — https://github.com/modelcontextprotocol/servers, retrieved 2026-09-29
- GITHUB COMMIT Merge remote-tracking branch 'security/fix-path-prefix-and-symlink' — github.com/modelcontextprotocol/servers, retrieved 2026-09-29
Public sample: the full evidence record is free.
Symptoms
- Files outside the allowed directories become accessible when their path prefix matches an allowed directory VERIFIED FACT
Context and trigger
- Agent type
- MCP client/agent using the Filesystem MCP server
- Component
- @modelcontextprotocol/server-filesystem path validation
- Framework
- Model Context Protocol reference servers (Filesystem) (<= 0.6.2 and >= 2025.1.14, < 2025.7.1)
- Model
- not stated
- Task
- file access through an MCP tool server
- Tools
- Filesystem MCP server
- A requested path shares a prefix with an allowed directory without being inside it VERIFIED FACT
Open questions
- The advisory text does not describe the validation code; details of the check come only from the fix branch name and changed files.
Root cause VERIFIED
Path validation accepted paths whose prefix matched an allowed directory (colliding path prefix) instead of requiring the path to be inside it.
cause stated by the project and addressed by an applied fix
could allow access to unintended files in cases where the prefix matches an allowed directoryRemediation attempts (1)
Security fix for path-prefix and symlink validation merged into the servers repository (new path-validation module with tests); users advised to upgrade to 2025.7.1.
Status basis: patched version published in advisory; regression test changed in the fix. Verification: regression test added with the fix; no independent confirmation that the original failure is gone.
Change: https://github.com/advisories/GHSA-hc55-p739-j48w · tests changed · released in 2025.7.1
Merge remote-tracking branch 'security/fix-path-prefix-and-symlink'
Users are advised to upgrade to 2025.7.1 to resolve the issue.Outcome outcome: RESOLVED UNVERIFIED
fix with regression test; no independent confirmation
Recurrence
Not documented in the sources (absence of reports is not evidence of absence).
Confidence HIGH
Root cause stated by the project, a fix was applied, and it is backed by a regression test or independent confirmation.
| Factor | Present | Meaning |
|---|---|---|
| first_party_evidence | yes | a quote from the affected project/vendor (or a controlled test) |
| fix_applied | yes | a fix was merged/released |
| regression_test | yes | tests changed with the fix |
| independent_confirmation | no | reporter/maintainer/vendor confirmed the failure is gone |
| root_cause_verified | yes | cause stated by the project and addressed by the fix |
| reproduction_documented | no | steps or conditions to reproduce were quoted |
| multiple_independent_sources | no | 1 independent source group(s) |
| failed_attempts_documented | no | unsuccessful remediation recorded |
All evidence (3 verified quotes)
could allow access to unintended files in cases where the prefix matches an allowed directoryMerge remote-tracking branch 'security/fix-path-prefix-and-symlink'
Users are advised to upgrade to 2025.7.1 to resolve the issue.Evidence-gate notes
- attempt 1: claimed VERIFIED_SUCCESS, evidence allows TESTED
Categories: SECURITY FAILURE AUTHORITY ERROR · extraction curated, gate-2026-09-29-v1
Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.