Path traversal in MCP Gateway - #VU139377

 

Path traversal in MCP Gateway - #VU139377

Published: July 26, 2026


Vulnerability identifier: #VU139377
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to path traversal in ResolveFile in workingset.go when processing a file:// server reference. A local user can supply a file:// reference to an arbitrary absolute host path to disclose sensitive information.

Only files that pass later content or extension validation are accepted as server definitions, which limits what data is reflected back.


Affected software

MCP Gateway

Remediation

Install security update from vendor's website.

MCP Gateway - update to 0.43.1

External References

Related Security Bulletins