Impact
appium-mcp-server up to version 0.1.61 does not validate or normalize file paths supplied to the write_file and write_files_batch utilities. An attacker can supply absolute paths or relative paths containing parent directory segments, causing the server to write files outside the intended PROJECT_ROOT directory. By overwriting arbitrary files such as shell profiles or configuration files in the home directory, an attacker may gain persistence, elevate privileges, or disrupt service operation.
Affected Systems
The affected product is appium-mcp-server from vendor argneshu, versions 0.1.61 and earlier. No other vendors or product versions are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, and although EPSS is not available, the flaw can be abused if an attacker can reach the file upload API. The vulnerability is not listed in the CISA KEV catalog, but the mechanics of path traversal make it likely to be exploitable remotely via the write_file or write_files_batch endpoints.
OpenCVE Enrichment