Impact
The vulnerability resides in the generateProjectDocs function of azer react‑analyzer‑mcp, where an attacker can supply a crafted projectName argument that bypasses the intended path resolution and walks outside the project directory. The flaw allows reading of arbitrary files that reside on the same machine, potentially exposing sensitive configuration, source code, or system files. Since the flaw is limited to path traversal and does not lead to arbitrary code execution or privilege escalation, its impact is primarily confidentiality loss of local data.
Affected Systems
azer's react‑analyzer‑mcp, up to commit 335f2a3585f265e2e88352b59b10d3b478d678b0, is affected. The project uses a rolling‑release model, so specific version numbers for the fix are not yet available. Users running any release that includes or predates that commit are at risk if the analyze‑project or generateProjectDocs feature is enabled.
Risk and Exploitability
The CVSS score of 4.8 classifies the issue as moderate, and the EPSS score is not available, so the current exploitation probability is unknown. The flaw can be leveraged only from a local environment, meaning that it is most relevant to insiders or an attacker who has compromised the host. Because the product has not yet released a patch and the vulnerability is not included in CISA's KEV list, the immediate risk level is low to moderate; however, organizations that rely on local function or run the tool in less‑trusted contexts should consider mitigating steps.
OpenCVE Enrichment