@modelcontextprotocol/server-filesystem
MCP server for filesystem access
Installing this server brings 133 third-party packages inside your agent's trust boundary (4 direct). This is attack surface, not a vulnerability count — it does not affect the grade above.
Findings (2)
- HIGH
VULN_KNOWN— GHSA-hc55-p739-j48w: @modelcontextprotocol/server-filesystem vulnerability allows for path validation bypass via colliding path prefix. See https://osv.dev/vulnerability/GHSA-hc55-p739-j48w - HIGH
VULN_KNOWN— GHSA-q66q-fx2p-7w4m: @modelcontextprotocol/server-filesystem allows for path validation bypass via prefix matching and symlink handling. See https://osv.dev/vulnerability/GHSA-q66q-fx2p-7w4m
Embed this badge
[](https://vulnrable.com/mcp/modelcontextprotocol--server-filesystem/) Automated registry-metadata scan; not a code audit. Rescanned on each site deploy.