
Path Traversal Vulnerability Discovered in MCP Server
CybersecurityVulnerabilitiesData LeaksSoftware Development
💬 We found a path traversal in an MCP server with 7,700 stars that lets AI agents read your SSH keys. Fix merged. The vulnerability was discovered in an MCP (Multi-Agent Collaboration Platform) server, allowing unauthorized access to sensitive files, including SSH keys, via a path traversal flaw. The affected project had 7,700 stars on its repository. A fix for the issue has been merged into the codebase.