


Perceptive Security
SOC/SIEM Consultancy

appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outs…
Published:
1 September 2026 at 00:00:00
Alert date:
1 September 2026 at 19:14:40
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies, Security Tools
appium-mcp-server versions through 0.1.61 contain a path traversal vulnerability in the write_file and write_files_batch tools. The server fails to validate or normalize file paths, allowing attackers to write files outside the intended PROJECT_ROOT directory. Attackers can exploit this by supplying absolute paths or relative paths containing parent directory segments (e.g., ../). This enables overwriting of arbitrary files with the privileges of the server user. Sensitive targets include shell profiles and configuration files located in the home directory. The vulnerability poses a significant risk as it can lead to privilege escalation or persistent backdoor installation. No authentication bypass is required beyond access to the MCP server tools.
Technical details
Mitigation steps:
Affected products:
appium-mcp-server 0.1.61 and earlier
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84201
https://github.com/argneshu/appium-mcp-server/blob/92b5c2b325e7bdd124f1f41a6049028b2a44e89c/src/mcp_server.py
https://github.com/argneshu/appium-mcp-server/blob/92b5c2b325e7bdd124f1f41a6049028b2a44e89c/src/tools/write_files_batch.py
https://www.npmjs.com/package/appium-mcp-server
https://www.vulncheck.com/advisories/appium-mcp-server-through-0.1.61-path-traversal-in-write-file-and-write-files-batch
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
