Impact
The vulnerability resides in the execute function of get-c2d.ts within the mcp__C2d component of mastergo-magic-mcp. By manipulating the filePath argument, an attacker can cause the application to reference files outside the intended directory, enabling the reading of arbitrary files on the host. This weakness aligns with CWE-22 and can compromise confidentiality or provide footholds for further exploits if sensitive system files or secrets are accessed.
Affected Systems
Any installation of mastergo-magic-mcp by mastergo-design with version 0.2.0 or older is affected. The vulnerability is documented against the product without a lower bound on the impacted versions, indicating that the entire release line up to 0.2.0 is vulnerable.
Risk and Exploitability
The CVSS score of 4.8 denotes moderate severity for a local‑access flaw, and the EPSS score of less than 1 % indicates a low probability of widespread exploitation. The CVE is not listed in the CISA KEV catalog. An attacker would need local execution on the host running the utility; a public exploit has been released, so any user with local access could trigger the traversal. Overall risk remains moderate until a vendor fix or a reliable mitigation measure is applied.
OpenCVE Enrichment