{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/faf-mcp--2.1.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["faf-mcp (\u003c= 2.1.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe faf-mcp package (versions 2.1.2 and earlier) contains a critical path traversal vulnerability caused by the insecure handling of the \u003ccode\u003epath\u003c/code\u003e argument in its MCP (Model Context Protocol) tools. The application resolves caller-provided paths using \u003ccode\u003e~\u003c/code\u003e expansion and \u003ccode\u003epath.resolve()\u003c/code\u003e without confining them to a trusted project directory. This flaw allows an attacker to bypass intended directory restrictions using absolute paths or directory traversal sequences (../). By sending crafted tool calls via an MCP client, an attacker can read sensitive files, such as SSH keys, AWS credentials, or system configuration files, and overwrite files on the host system where the faf-mcp server process has sufficient permissions. This vulnerability was identified during a security audit and is remediated in version 2.1.3 through robust path canonicalization and directory confinement.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to perform unauthorized file system operations, leading to potential credential theft, information disclosure, and system compromise. Attackers can reach critical files such as \u003ccode\u003e~/.ssh/id_rsa\u003c/code\u003e, \u003ccode\u003e~/.aws/credentials\u003c/code\u003e, and \u003ccode\u003e/etc/passwd\u003c/code\u003e. Because the server operates over stdio and responds to tool calls, this vulnerability is highly susceptible to exploitation through LLM prompt injection, where an agent processing malicious external content is coerced into executing these unauthorized file operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to faf-mcp version 2.1.3 or later immediately to apply the path confinement logic in \u003ccode\u003esafe-path.ts\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately feasible, restrict the use of the server to trusted environments and define the \u003ccode\u003eFAF_ALLOWED_ROOTS\u003c/code\u003e environment variable to explicitly bound access to a single, low-risk project directory.\u003c/li\u003e\n\u003cli\u003eImplement endpoint monitoring to detect unauthorized file access patterns from the faf-mcp process (or the parent node process) targeting sensitive configuration paths outside the expected working directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T22:34:43Z","date_published":"2026-08-19T22:34:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-faf-mcp-path-traversal/","summary":"The faf-mcp package contains an arbitrary local file read/write vulnerability due to failure to validate user-supplied path arguments, allowing attackers to access or modify sensitive files outside the project directory.","title":"Arbitrary Local File Read and Write in faf-mcp","url":"https://feed.craftedsignal.io/briefs/2026-08-faf-mcp-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Faf-Mcp (\u003c= 2.1.2)","version":"https://jsonfeed.org/version/1.1"}