A path traversal vulnerability has been identified in dekdee adobe-xd-mcp version 1.0.0. The flaw exists in the file src/parsers/xd-parser.ts within the file-access-from-request endpoint. Attackers can manipulate the outputFile or outputDir arguments to traverse the file system beyond intended directories. The vulnerability can be exploited remotely, increasing its risk surface significantly. A public exploit is already available, raising the threat level for any exposed instances. The project maintainer was notified via a GitHub issue but has not responded or issued a patch. No workaround has been officially provided at this time. The combination of public exploit availability and lack of vendor response makes this a high-priority concern.