


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file s…
Published:
27 August 2026 at 00:00:00
Alert date:
27 August 2026 at 07:00:41
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies, Zero-Day Vulnerabilities
A path traversal vulnerability has been identified in boxpositron with-context-mcp up to version 3.0.7. The flaw exists in the functions ingest_notes, teleport_notes, sync_notes, and project_folder within the file src/index.ts. An attacker can exploit this vulnerability remotely by manipulating input to traverse file system paths beyond intended boundaries. A public exploit has already been published and is potentially being used in the wild. The project maintainer was notified via an issue report but has not yet responded or issued a fix. This presents an active risk to users running affected versions of the package.
Technical details
Mitigation steps:
Affected products:
boxpositron with-context-mcp up to 3.0.7
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-81491
http://github.com/boxpositron/with-context-mcp/issues/2
https://vuldb.com/cve/CVE-2026-81491
https://vuldb.com/submit/887138
https://vuldb.com/vuln/395981
https://vuldb.com/vuln/395981/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
