Jenn Newton

3 exploits Active since Jul 2025
CVE-2025-53109 WRITEUP HIGH WRITEUP
Model Context Protocol Servers < 0.6.4 and < 2025.7.01 - Unintended File Access via Symlink Resolution
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files via symlinks within allowed directories. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve.
CVE-2025-53110 WRITEUP HIGH WRITEUP
Model Context Protocol Servers < 0.6.4 and < 2025.7.01 - Path Traversal
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files in cases where the prefix matches an allowed directory. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve.
CVE-2025-58444 WRITEUP HIGH WRITEUP
MCP Inspector < 0.16.6 - Cross-Site Scripting via Malicious Redirect URI
The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This could be leveraged to interact directly with the inspector proxy to trigger arbitrary command execution. Users are advised to update to 0.16.6 to resolve this issue.