top of page
perceptive_background_267k.jpg

A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file s…

Published:

27 August 2026 at 00:00:00

Alert date:

27 August 2026 at 07:00:41

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies, Zero-Day Vulnerabilities

A path traversal vulnerability has been identified in boxpositron with-context-mcp up to version 3.0.7. The flaw exists in the functions ingest_notes, teleport_notes, sync_notes, and project_folder within the file src/index.ts. An attacker can exploit this vulnerability remotely by manipulating input to traverse file system paths beyond intended boundaries. A public exploit has already been published and is potentially being used in the wild. The project maintainer was notified via an issue report but has not yet responded or issued a fix. This presents an active risk to users running affected versions of the package.

Technical details

Mitigation steps:

Affected products:

boxpositron with-context-mcp up to 3.0.7

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page