Executive Summary
Anthropic has issued a critical security advisory addressing CVE-2026-70114, an unauthorized directory traversal and sandbox escape vulnerability within reference implementations of the Model Context Protocol (MCP) Filesystem Server. The flaw, assigned a CVSS v3.1 score of 9.3 (Critical), allows autonomous tool-calling agents—including Claude Code, Cursor, and custom enterprise agentic harnesses—to traverse outside designated workspace directories and read arbitrary host filesystem assets.
The Model Context Protocol has emerged as the industry standard for bridging large language models (LLMs) with external tools, databases, and local file systems. CVE-2026-70114 represents a foundational vulnerability in the agentic boundary: when an LLM is manipulated via indirect prompt injection (e.g., analyzing an untrusted repository or web page), malicious instructions can force the MCP server to exfiltrate private developer credentials, SSH keys, and cloud tokens.
Root Cause Analysis: Symlink and Path Normalization Gap
The reference @modelcontextprotocol/server-filesystem exposes standard RPC endpoints such as read_file, write_file, and list_directory. While the server enforced checks against explicit relative paths containing ../, it failed to properly resolve symlinks and Windows UNC paths before performing boundary verification.
Specifically, using percent-encoded or double-encoded path separators (e.g., ..%252f or non-normalized unicode equivalents) in tool call parameters caused Node.js path.resolve() to process the path inconsistently compared to the sandbox root validator:
// Vulnerable MCP Server Path Validation Logic
function isPathInsideRoot(targetPath: string, allowedRoot: string): boolean {
// VULNERABLE: Direct string prefix comparison without realpath symlink resolution
const resolvedTarget = path.resolve(allowedRoot, targetPath);
return resolvedTarget.startsWith(allowedRoot);
}
// Exploit Payload:
// targetPath = "..%252f..%252f..%252fhome/user/.ssh/id_ed25519"
// Resolves outside allowedRoot when decoded by downstream filesystem hooks
Attack Mechanics: Indirect Prompt Injection to Tool Compromise
The primary risk scenario arises when developers authorize autonomous coding agents to evaluate external codebases, pull requests, or issue trackers:
- Poisoned Context Ingestion: The agent reads a repository containing a hidden instruction embedded within a README, issue comment, or code docstring.
- Instruction Hijack: The prompt directs the agent to invoke the MCP tool
read_filetargeting../../../../.aws/credentials. - Boundary Check Failure: Due to CVE-2026-70114, the MCP server evaluates the request as legitimate, reads the host credentials, and passes them back into the LLM context window.
- Exfiltration: Subsequent tool invocations (such as an automated curl or git push command) exfiltrate the secret tokens to an external attacker endpoint.
Remediation & Defense-in-Depth Checklist
Developers and enterprise security teams deploying Model Context Protocol servers must implement the following controls immediately:
- Upgrade MCP Server Packages: Immediately update
@modelcontextprotocol/server-filesystemto version1.4.0or higher across all developer workstations and CI/CD pipelines. - Enforce Canonical Realpath Validation: Ensure that custom MCP tool servers verify paths using
fs.realpathSync()against an explicit allowlist of authorized directory paths. - Containerize Local Agent Environments: Run coding assistants and agent runners inside lightweight ephemeral Docker containers or macOS/Linux sandboxes rather than granting bare-metal host filesystem access.
- Mandate Confirmation Prompts: Keep user confirmation dialogs active for tool calls touching sensitive paths (e.g., dotfiles,
.ssh,.env, and cloud credential directories).



