THREATOPS
THREAT OPSThreat News › Survey of filesystem MCP servers: how the "sandboxed filesystem" boundary is enforced (one breach, four defended-by-design)

Survey of filesystem MCP servers: how the "sandboxed filesystem" boundary is enforced (one breach, four defended-by-design)

lowoss_secPublished 2026-09-10

<p>Posted by Eve on Sep 09</p>Summary<br /> =======<br /> I surveyed five filesystem MCP servers that operate on a host filesystem and assessed how each enforces its<br /> &quot;only these paths are available&quot; boundary, specifically against a symlink escape in a recursive directory<br /> walker. One (iceener/files-stdio-mcp-server) is vulnerable to a read-side sandbox escape; the other four a

Original source: https://seclists.org/oss-sec/2026/q3/703