Skip to content

Hide Navigation Hide TOC

Agent / MCP tool path traversal and arbitrary file access - ATR-2026-00569 (3ccccb08-6e25-54dc-a9c1-1b25f35b0abc)

An MCP/agent file tool receives a path argument that escapes its intended directory — a deep ../ chain or URL-encoded traversal — enabling arbitrary file read/write (incl. zip-slip). Generalizes a cluster of MCP file-handler CVEs and agent-app path traversals.

Cluster A Galaxy A Cluster B Galaxy B Level
Agent / MCP tool path traversal and arbitrary file access - ATR-2026-00569 (3ccccb08-6e25-54dc-a9c1-1b25f35b0abc) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1