Impact
The vulnerability arises from the _validate_file_path function in tumf's mcp-text-editor, which fails to enforce proper path validation. This flaw is a CWE-22 path traversal weakness that allows an attacker to supply a crafted file_path string that navigates outside of the intended directory, potentially enabling remote reading or overwriting of arbitrary files on the host system. The flaw directly compromises be performed from a remote location, as the attack is triggered through input parameters sent to the editor.
Affected Systems
The issue affects tumf's mcp-text-editor product up to and including version 1.0.2. Any installation of the software that has not been updated beyond that release is susceptible, regardless of the operating system or deployment configuration.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, which exploitation. Nevertheless, the public disclosure and remote attack potential mean that attackers may eventually craft exploit payloads should the software remain unpatched.
OpenCVE Enrichment