{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3a03_lovepreetsinghmcp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:03_lovepreetsingh:mcp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-94044"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MCP (\u003c= f95d035c5317fad81af9828286631053ccb23546)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","path-traversal","cve-2026-94044"],"_cs_type":"advisory","_cs_vendors":["03-lovepreetSingh"],"content_html":"\u003cp\u003eA path traversal vulnerability exists in the MCP project developed by 03-lovepreetSingh, specifically affecting all revisions up to f95d035c5317fad81af9828286631053ccb23546. The vulnerability resides in the create_file function located within the app/api/mcp/route.ts file. By manipulating the filePath or content arguments in a network-accessible request, an unauthenticated remote attacker can write files to arbitrary locations on the host filesystem. This project does not utilize standard versioning, making remediation difficult without verifying the specific commit hash. As of the report date, public exploit code is available for this vulnerability, and the project maintainers have not issued a response or patch to address the underlying flaw. Defenders should treat this as a high-priority risk for internet-facing instances of the affected application.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-94044 allows a remote attacker to write arbitrary files to the server's filesystem. Depending on the application's environment and permissions, this could lead to the deployment of malicious scripts, modification of configuration files, or the achievement of remote code execution. Given the availability of public exploit code, the risk of exploitation by opportunistic threat actors is significant. Organizations hosting MCP instances are advised to restrict external access to the affected API endpoint until a security fix is verified and deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests directed at /api/mcp/route.ts containing directory traversal patterns such as \u0026quot;../\u0026quot; or absolute file paths.\u003c/li\u003e\n\u003cli\u003eAudit deployments to determine if the installed version is at or below commit hash f95d035c5317fad81af9828286631053ccb23546.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation or web application firewall (WAF) rules to block requests containing path traversal sequences directed at the create_file endpoint.\u003c/li\u003e\n\u003cli\u003eDisable the affected API endpoint at the network or application level until a validated patch is provided by the project maintainers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-20T20:23:06Z","date_published":"2026-09-20T20:23:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-94044/","summary":"The MCP project is vulnerable to remote path traversal exploitation via the create_file function in app/api/mcp/route.ts, allowing for unauthorized file manipulation.","title":"Path Traversal Vulnerability in MCP","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-94044/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:03_lovepreetsingh:mcp:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}