AE Agent Errors
AE-YKAMK5PX

Filesystem MCP server grants access to files in directories whose path only shares a prefix with an allowed directory

SECURITY FAILUREseverity: HIGHcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: HIGH

The reference Filesystem MCP server validated requested paths against its allowed directories in a way that accepted paths whose prefix matched an allowed directory, so an agent using the server could access unintended files outside the allowed directories. It was fixed in a security branch addressing path-prefix and symlink validation, released as 2025.7.1.

Framework / agent
Model Context Protocol reference servers (Filesystem) · MCP client/agent using the Filesystem MCP server
Remediation attempts
TESTED
Recurrence
not documented
Source languages
en, und-Latn
Updated
2026-09-30

Sources

Public sample: the full evidence record is free.

Symptoms

  • Files outside the allowed directories become accessible when their path prefix matches an allowed directory VERIFIED FACT

Context and trigger

Agent type
MCP client/agent using the Filesystem MCP server
Component
@modelcontextprotocol/server-filesystem path validation
Framework
Model Context Protocol reference servers (Filesystem) (<= 0.6.2 and >= 2025.1.14, < 2025.7.1)
Model
not stated
Task
file access through an MCP tool server
Tools
Filesystem MCP server
  • A requested path shares a prefix with an allowed directory without being inside it VERIFIED FACT

Open questions

  • The advisory text does not describe the validation code; details of the check come only from the fix branch name and changed files.

Root cause VERIFIED

Path validation accepted paths whose prefix matched an allowed directory (colliding path prefix) instead of requiring the path to be inside it.

cause stated by the project and addressed by an applied fix

could allow access to unintended files in cases where the prefix matches an allowed directorymaintainer · https://github.com/modelcontextprotocol/servers

Remediation attempts (1)

TESTEDpath_validationby maintainer

Security fix for path-prefix and symlink validation merged into the servers repository (new path-validation module with tests); users advised to upgrade to 2025.7.1.

Status basis: patched version published in advisory; regression test changed in the fix. Verification: regression test added with the fix; no independent confirmation that the original failure is gone.

Change: https://github.com/advisories/GHSA-hc55-p739-j48w · tests changed · released in 2025.7.1

Merge remote-tracking branch 'security/fix-path-prefix-and-symlink'maintainer · github.com/modelcontextprotocol/servers
Users are advised to upgrade to 2025.7.1 to resolve the issue.maintainer · https://github.com/modelcontextprotocol/servers

Outcome outcome: RESOLVED UNVERIFIED

fix with regression test; no independent confirmation

Recurrence

Not documented in the sources (absence of reports is not evidence of absence).

Confidence HIGH

Root cause stated by the project, a fix was applied, and it is backed by a regression test or independent confirmation.

FactorPresentMeaning
first_party_evidenceyesa quote from the affected project/vendor (or a controlled test)
fix_appliedyesa fix was merged/released
regression_testyestests changed with the fix
independent_confirmationnoreporter/maintainer/vendor confirmed the failure is gone
root_cause_verifiedyescause stated by the project and addressed by the fix
reproduction_documentednosteps or conditions to reproduce were quoted
multiple_independent_sourcesno1 independent source group(s)
failed_attempts_documentednounsuccessful remediation recorded

All evidence (3 verified quotes)

could allow access to unintended files in cases where the prefix matches an allowed directorymaintainer · https://github.com/modelcontextprotocol/servers
Merge remote-tracking branch 'security/fix-path-prefix-and-symlink'maintainer · github.com/modelcontextprotocol/servers
Users are advised to upgrade to 2025.7.1 to resolve the issue.maintainer · https://github.com/modelcontextprotocol/servers

Evidence-gate notes

  • attempt 1: claimed VERIFIED_SUCCESS, evidence allows TESTED

Categories: SECURITY FAILURE AUTHORITY ERROR · extraction curated, gate-2026-09-29-v1

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.