Impact
The vulnerability resides in the create_system_json/create_library functions within src/index.ts of advanced‑reasoning‑mcp version 1.0.0. It allows a local attacker to manipulate file paths so that the application reads or writes files outside the intended directory, exposing sensitive data or enabling further local exploitation. The weakness is a classic CWE‑22 path traversal flaw.
Affected Systems
The affected product is angrysky56 advanced‑reasoning‑mcp, version 1.0.0. No other versions or patches are listed in the CNA data.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV, suggesting limited known exploitation. The attack requires local access, so remote exploitation is not possible without additional compromise. Because of the local nature of the vulnerability and the absence of public exploit data, the overall risk is moderate for environments where the library runs with elevated privileges or has access to sensitive files.
OpenCVE Enrichment