Impact
A path‑traversal flaw exists in the create_file handler of a web service where user supplied file paths and content are used to create files on the server. By manipulating the filePath argument an attacker can place files outside the intended directory, potentially overwriting or creating critical system files. The flaw is exploitable from a remote request, and publicly available exploit code indicates that the attack can be deployed directly over the network.
Affected Systems
The affected product is the 03‑lovepreetSingh MCP project. Product releases up to commit f95d035c5317fad81af9828286631053ccb23546 are known to contain the vulnerability. Because the repository contains no proper versioning, the status of later commits is uncertain; any deployment of the pre‑commit code is at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, however the existence of publicly available exploitation scripts and the remote launchability elevate the practical risk. Attackers can send a crafted API request to the create_file endpoint to create or overwrite files on the host filesystem, potentially enabling privilege escalation or persistence if the service runs with elevated permissions.
OpenCVE Enrichment