{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/boxpositron/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-81491"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["with-context-mcp (\u003c= 3.0.7)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","vulnerability","remote-code-execution"],"_cs_type":"threat","_cs_vendors":["boxpositron"],"content_html":"\u003cp\u003eA path traversal vulnerability has been identified in the boxpositron with-context-mcp package, affecting versions up to 3.0.7. The flaw resides within the ingest_notes, teleport_notes, sync_notes, and project_folder functions located in src/index.ts. By supplying maliciously crafted inputs to these functions, a remote attacker can bypass intended file system restrictions to access or manipulate files outside of the application's designated scope. Publicly available exploit code exists for this vulnerability, and as of the reporting date, the maintainers have not issued a patch. This vulnerability poses a significant risk to systems utilizing this component for document or note processing, as it enables unauthorized file system operations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-81491 allows unauthenticated remote attackers to access unauthorized files on the underlying host system, potentially leading to the disclosure of sensitive information or the modification of configuration files. The lack of a patch means all deployments of the affected versions are currently vulnerable to exploitation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit environments to identify all instances of the with-context-mcp package and confirm the installed version.\u003c/li\u003e\n\u003cli\u003eUntil an official patch is released by the maintainers, implement strict input validation for all data passed to the ingest_notes, teleport_notes, sync_notes, and project_folder functions to prevent directory traversal sequences (e.g., \u0026quot;../\u0026quot;).\u003c/li\u003e\n\u003cli\u003eRestrict access to services running with-context-mcp by placing them behind a WAF or VPN, limiting the potential for remote exploitation by unauthorized parties.\u003c/li\u003e\n\u003cli\u003eMonitor file system logs for unexpected access patterns originating from the application user or service account.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T05:33:59Z","date_published":"2026-08-27T05:33:59Z","id":"https://feed.craftedsignal.io/briefs/2026-08-path-traversal-with-context-mcp/","summary":"A publicly disclosed path traversal vulnerability (CVE-2026-81491) in boxpositron with-context-mcp versions 3.0.7 and earlier allows remote attackers to manipulate file paths via specific ingested note functions.","title":"Path Traversal Vulnerability in with-context-mcp","url":"https://feed.craftedsignal.io/briefs/2026-08-path-traversal-with-context-mcp/"}],"language":"en","title":"CraftedSignal Threat Feed - Boxpositron","version":"https://jsonfeed.org/version/1.1"}