CVE-2025-53109: Modelcontextprotocol Servers
High severity, CVSS 7.3. EPSS: 0.8% chance of exploitation in the next 30 days.
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directories. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve.
Affected products
- Modelcontextprotocol Servers: before 0.6.4 (fixed in 0.6.4); before 2025.7.01 (fixed in 2025.7.01)
Published 2025-07-02. Last modified 2026-06-17.