Product
The faf-mcp package contains an arbitrary local file read/write vulnerability due to failure to validate user-supplied path arguments, allowing attackers to access or modify sensitive files outside the project directory.