{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/appium-mcp-server--0.1.61/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:appium:appium-mcp-server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-84201"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["appium-mcp-server (\u003c= 0.1.61)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","appium","cve-2026-84201"],"_cs_type":"advisory","_cs_vendors":["Appium"],"content_html":"\u003cp\u003eThe appium-mcp-server package, specifically versions up to and including 0.1.61, is susceptible to a path traversal vulnerability within the \u003ccode\u003ewrite_file\u003c/code\u003e and \u003ccode\u003ewrite_files_batch\u003c/code\u003e tools. This flaw arises from a critical lack of input validation and path normalization when handling file path arguments. An attacker can exploit this by providing malicious file paths - including absolute paths or relative paths containing directory traversal sequences like \u0026quot;../\u0026quot; - to escape the intended \u003ccode\u003ePROJECT_ROOT\u003c/code\u003e directory.\u003c/p\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to overwrite arbitrary files on the host system. The impact of this vulnerability is significant, as the overwritten file content is written with the privileges of the underlying server process. Attackers can target shell profiles (e.g., .bashrc or .zshrc), SSH authorized_keys files, or service configuration files to facilitate persistence or achieve arbitrary command execution. This vulnerability is particularly dangerous in environments where the server runs with elevated or high-privileged user access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for unauthorized file modification, which can lead to complete system compromise via remote code execution or credential theft. If the server process runs as a privileged user, an attacker can modify system-wide configuration files or user-specific shell initialization scripts, enabling code execution upon the next login or service restart. No specific victim sector is targeted; the vulnerability affects all deployments of appium-mcp-server version 0.1.61 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the appium-mcp-server package to a version beyond 0.1.61 that includes path normalization or strict directory validation for file operations.\u003c/li\u003e\n\u003cli\u003eAudit file system access logs for the process user running the appium-mcp-server to detect unauthorized writes to locations outside the designated project root directory.\u003c/li\u003e\n\u003cli\u003eRun the appium-mcp-server process under a restricted, low-privilege service account to limit the impact of potential arbitrary file overwrites.\u003c/li\u003e\n\u003cli\u003eEnforce strict file system permissions on critical configuration directories and user profile files to prevent unauthorized modification by the service user.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T17:07:05Z","date_published":"2026-09-01T17:07:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-84201/","summary":"The appium-mcp-server package up to version 0.1.61 contains a path traversal vulnerability in file writing tools, allowing unauthenticated attackers to overwrite sensitive system files.","title":"Arbitrary File Write in appium-mcp-server via Path Traversal","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-84201/"}],"language":"en","title":"CraftedSignal Threat Feed - Appium-Mcp-Server (\u003c= 0.1.61)","version":"https://jsonfeed.org/version/1.1"}