THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-j4r7-8ph4-43g3 (high) — faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

[GHSA] GHSA-j4r7-8ph4-43g3 (high) — faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

medgithub_advisoriesPublished 2026-08-19

GHSA-j4r7-8ph4-43g3 Severity: high CVE: None

faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

### Summary `faf-mcp` MCP tools accept a caller-controlled `path` argument and resolve it (`~` expansion + `path.resolve()`) straight into a filesystem read/write **without confining it to a trusted project directory**. An absolute path or `../` traversal is res

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-j4r7-8ph4-43g3