Impact
A path traversal flaw exists in the ControlFlowNode function of the mcp-file-analyzer tool where manipulation of the filename argument can lead to reading or overwriting arbitrary files on the host. The CVE description explicitly states that the exploit is publicly available and can be performed remotely. Based on the description, it is inferred that an unauthenticated remote user could influence the filename argument to request files outside the intended directory, potentially exposing sensitive data or enabling remote code execution if configuration files or scripts are affected.
Affected Systems
The vulnerability affects all releases of 00Kisumi00's mcp-file-analyzer prior to the commit 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. Because the project follows a rolling release model, no specific version numbers are published, so any copy of the tool built before the stated commit is at risk.
Risk and Exploitability
The CVSS score of 5.3 places this issue in the medium severity range. EPSS is not available, and the vulnerability is not listed in CISA's KEV catalog. No particular prerequisites are mentioned, but remote exploitation is possible, so the likelihood of attack hinges on the tool’s exposure; a public-facing interface or unrestricted local execution would increase risk. Attackers can exploit the flaw by crafting a request that includes a path traversal sequence in the filename argument to gain unauthorized file access.
OpenCVE Enrichment