Mobile MCP Path Traversal CVE-2026-33989: Arbitrary File Write via Screenshot and Screen Recording Tools (CVSS 8.1)
GitLab Advisory·high signal
@mobilenext/mobile-mcp versions before 0.0.49 contain a path traversal vulnerability in mobile_save_screenshot and mobile_start_screen_recording tools — saveTo/output parameters accept directory traversal sequences without validation, enabling arbitrary file writes anywhere on the filesystem. CVSS 8.1 (high), no authentication required. Fixed in v0.0.49, disclosed March 27. This is the second major MCP CVE in March after Azure's CVE-2026-26118.