Vibe Coding
mcp-file-context-server Path Traversal Has a Public Exploit and No Maintainer Response (CVE-2026-81486)
CVE-2026-81486, published to NVD 2026-08-27 and to GitHub Security Advisories at 03:32 UTC the same day as GHSA-r93x-r7qx-vp33, is a path traversal in the read_context function of src/index.ts in bsmi021 mcp-file-context-server 1.0.0. It is remotely exploitable via the path argument and rated 5.5 MEDIUM. NVD's text notes the project was informed early through an issue report and the exploit is now public — a file-reading MCP server with a live traversal and no fix is a straightforward path from prompt injection to arbitrary file disclosure.
Source
↳ Follow the thread