T09 · Insecure Skill Coding Practices
- Location
references/resources-and-prompts.md:48- Finding
Workspace Resource Scaffold Permits Arbitrary Filesystem Reads
- Content
View full analysis
Vulnerability Details
File Location:
references/resources-and-prompts.md:48-64
Vulnerability Type: Unrestricted file path access / path traversal
Risk Level: MediumVulnerable Code
typescript import { ResourceTemplate } from "@modelcontextprotocol/sdk/server/mcp.js"; server.registerResource( "file", new ResourceTemplate("file:///{path}", { list: undefined }), { name: "File", description: "Read a file from the workspace" }, async (uri, { path }) => ({ contents: [{ uri: uri.href, text: await fs.readFile(path, "utf8") }], }), );python @mcp.resource("file:///{path}") def read_file(path: str) -> str: return Path(path).read_text()Technical Analysis
The documented TypeScript and Python resource implementations pass the client-controlled
{path}URI component directly to filesystem APIs. Neither implementation resolves the path relative to an approved workspace root, rejects absolute paths or traversal components, canonicalizes the target, or verifies that the resolved file remains inside the intended workspace.This contradicts the resource description, which states that the handler reads files “from the workspace.” In practice, filesystem access is limited only by the operating-system permissions of the MCP server process.
Because this file is an implementation reference used when building MCP servers, a server generated from the scaffold inherits the unsafe behavior. The vulnerability becomes reachable when an MCP client is allowed to request resources from that generated server.
Attack Path
- A developer adopts the documented
file:///{path}resource template in an MCP server. - The server is started with access to workspace files and potentially other files readable by its operating-system account.
- An unauthorized or malicious MCP client requests a crafted resource URI whose
{path}is an absolute path or contains traversal compon ...[truncated 1036 chars]
- A developer adopts the documented
- Remediation
View remediation
Remediation Suggestions
- Configure an explicit workspace root rather than accepting unrestricted filesystem paths.
- Parse and decode the resource path once, reject absolute paths, and reject traversal components.
- Resolve the requested path against the configured root and canonicalize both the root and target.
- Verify that the canonical target is the root itself or a descendant of it using path-aware containment checks; do not rely on string-prefix comparison alone.
- Prevent symlink escapes by resolving real paths before opening files or by using platform facilities that constrain filesystem access beneath a directory.
- Restrict resource access to authenticated and authorized clients where files are not public.
- Consider exposing opaque resource identifiers or an allowlisted resource catalog instead of raw filesystem paths.
- Add tests covering absolute paths, encoded traversal, mixed separators, symlink escapes, and sibling directories with similar prefixes.
