Impact
The vulnerability resides in the processGenerateRequest function of the generate_mermaid_markdown component. An attacker can supply a crafted folder/name argument that leads the server to resolve a path outside the intended directory. This allows reading of files beyond the intended scope and could compromise the confidentiality of sensitive configuration or system files. The description does not indicate the ability to modify files, only read access.
Affected Systems
Automateyournetwork’s MCPyATS product, versions up to 0.1.4, includes the file mcp_servers/mermaid/index.ts used for generating Mermaid markdown. No other vendors or product versions are listed as affected.
Risk and Exploitability
The CVSS score is 4.8, reflecting a moderate severity. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires local access, so the threat is limited to users who can run the MCPyATS service or otherwise invoke the vulnerable endpoint. Given the local nature, the likelihood of widespread exploitation is lower than remote vulnerabilities, but local privilege escalation or compromise of the hosting system could expose sensitive data.
OpenCVE Enrichment