chiprook
← Security
SecurityOctober 2, 2026, 22:20

MCPVault path filters bypassed: CVE-2026-57441 and CVE-2026-57442

Two advisories in MCPVault, which restricts which directories a language model can read, describe path-filter bypasses: CVE-2026-57441 (CVSS 8.4) and CVE-2026-57442 (CVSS 6.9). Both stem from comparing a path as a string instead of the filesystem-resolved path.

MCPVault path filters bypassed: CVE-2026-57441 and CVE-2026-57442
#MCPVault
Read next
Security

CVE-2026-48710 (BadHost): malformed Host header bypasses Starlette path authorization

Security

Exploit details for Citrix NetScaler CVE-2026-88772 reveal pre-auth shellcode path

Security

Two RouterOS Bugs, One Escalation Path: What CVE-2026-67277 and CVE-2026-86060 Mean for Edge Routers

Security

CVE-2026-92957: vm2 sandbox escape via node: prefix bypass