THREAT OPS › Threat News › [GHSA] GHSA-cc2g-gq8c-r332 (high) — grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
[GHSA] GHSA-cc2g-gq8c-r332 (high) — grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
GHSA-cc2g-gq8c-r332 Severity: high CVE: None
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
### Summary Several `grok-faf-mcp` MCP tools accept a caller-controlled `path` argument and resolve it (`~` expansion + `path.resolve()`) straight into a filesystem read **without confining it to a trusted project directory**. An absolute path or `../` traversal
MITRE ATT&CK techniques
- CredentialsT1589.001
Original source: https://github.com/advisories/GHSA-cc2g-gq8c-r332