Impact
The vulnerability arises in the ingest_notes, teleport_notes, and sync_notes functions, allowing a supplied project_folder value to bypass sanitization and traverse directories. This flaw can lead to arbitrary file read or write relative to the application's base directory, enabling an attacker to access or modify sensitive data. The CVSS score of 6.9 reflects moderate to high risk, and the issue is classified as CWE-22.
Affected Systems
The affected product is boxpositron with-context-mcp, specifically versions up to and including 3.0.7. No later releases are known to be impacted.
Risk and Exploitability
The flaw can be exploited remotely by delivering a crafted request that includes a malicious project_folder path. An exploit has already been published and may currently be used. While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the combination of a CVSS of 6.9 and the ease of remote exploitation suggests a significant risk for systems that remain unpatched.
OpenCVE Enrichment