---
id: CVE-2026-79534
title: >-
  mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal
  due to an improper link resolution in validatePath
  (filesystemserver/handler/helper.go)
summary: >-
  mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal
  due to an improper link resolution in validatePath
  (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns
  os.IsNotExist for a dangling symlink…
severity: none
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T20:17:26.993'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79534'
references:
  - url: 'https://www.traceforce.ai/security-advisories/cve-2026-79534'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T19:44:04.153Z'
---

## Overview

mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved path, so write_file (and modify_file, copy_file, move_file, create_directory) follows a pre-existing dangling symlink located inside an allowed directory and creates a file outside the configured allowed directories.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
