Impact
The markdownify-mcp library contains a defect in its assertPathAllowed function that allows a crafted path to trigger the operating system to follow a symbolic link. This path manipulation enables a local user to read or potentially modify files that are outside the intended directory. The vulnerability is a classic symlink traversal flaw, described explicitly as a symlink-following weakness in the source code.
Affected Systems
Versions of zcaceres markdownify-mcp up to and including 1.1.0 are vulnerable. No other vendors or products are listed as affected in the current record.
Risk and Exploitability
The CVSS score of 4.8 places the issue in the medium severity range, while the EPSS score of less than 1% probability of real-world exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the attack vector is already have the ability to execute code or otherwise influence the host running the library; remote exploitation is not supported by the information provided.
OpenCVE Enrichment