CVE-2025-66689

MEDIUM

Zen MCP Server <9.8.2 - Path Traversal

Title source: llm
STIX 2.1

Description

A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitrary files on the system. The vulnerability is caused by flawed logic in the is_dangerous_path() validation function that uses exact string matching against a blacklist of system directories. Attackers can bypass these restrictions by accessing subdirectories of blacklisted paths.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 13.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22 CWE-552
Status published
Products (1)
busymac/pal_mcp_server < 9.8.2
Published Jan 12, 2026
Tracked Since Feb 18, 2026