Tag
The MCP project is vulnerable to remote path traversal exploitation via the create_file function in app/api/mcp/route.ts, allowing for unauthorized file manipulation.