CVE-2025-53110: Modelcontextprotocol Servers
High severity, CVSS 7.3. EPSS: 0.6% chance of exploitation in the next 30 days.
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files in cases where the prefix matches an allowed directory. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve.
Affected products
- Modelcontextprotocol Servers: before 0.6.4 (fixed in 0.6.4); before 2025.7.01 (fixed in 2025.7.01)
Published 2025-07-02. Last modified 2026-06-17.