← Terug naar overzicht

A path traversal vulnerability has been identified in boxpositron with-context-mcp up to version 3.0.7. The flaw exists in the functions ingest_notes, teleport_notes, sync_notes, and project_folder within the file src/index.ts. An attacker can exploit this vulnerability remotely by manipulating input to traverse file system paths beyond intended boundaries. A public exploit has already been published and is potentially being used in the wild. The project maintainer was notified via an issue report but has not yet responded or issued a fix. This presents an active risk to users running affected versions of the package.

Affected products

  • boxpositron with-context-mcp up to 3.0.7

Related CVE's

  • CVE-2026-81491

Categories

  • Supply Chain & Dependencies
  • Web Technologies
  • Zero-Day Vulnerabilities