---
title: "EscapeRoute: Filesystem MCP server sandbox escape · DotsAgent"
description: "Cymulate found a sandbox escape and a symlink bypass in Anthropic's Filesystem MCP server, letting it reach files outside the directories it was allowed to use."
url: https://dotsagent.io/security/incidents/2025-07-filesystem-mcp-escaperoute
---

July 1, 2025

CVE-2025-53109

CVE-2025-53110

# EscapeRoute: Filesystem MCP server sandbox escape

Cymulate found a sandbox escape and a symlink bypass in Anthropic's Filesystem MCP server, letting it reach files outside the directories it was allowed to use.

## What happened

Cymulate disclosed two flaws, which it named EscapeRoute, in Anthropic's Filesystem MCP server: a sandbox escape and a symlink bypass, tracked as CVE-2025-53109 and CVE-2025-53110. The server is meant to confine an agent to a list of allowed directories, and both flaws let it step outside them.

Fixes shipped in versions 0.6.4 and 2025.7.01.

## Why it worked

The directory restriction depended on the server's own path checks. Once those checks could be fooled, for example by a symbolic link pointing elsewhere, nothing else stopped the process from reading or writing outside the allowed paths.

## What to do

- Update the Filesystem MCP server to a fixed release.
- Run file-access servers in a container that mounts only the project directory.
- Don't rely on an MCP server's own allowlist as your only boundary.
- Keep credentials and SSH keys out of any directory an agent can reach.

[Sandbox code and tool execution](https://dotsagent.io/security#sandboxing)[Use least-privilege credentials](https://dotsagent.io/security#leastPrivilege)

- [mcp-remote OS command injection via authorization_endpoint](https://dotsagent.io/security/incidents/2025-07-mcp-remote-os-command-injection)

- [Supabase MCP agent leaks tokens through a support ticket](https://dotsagent.io/security/incidents/2025-07-supabase-mcp-token-leak)

[Work through the security checklist →](https://dotsagent.io/security/checklist)

## Sources

1. [cymulate.com](https://cymulate.com/blog/cve-2025-53109-53110-escaperoute-anthropic/)/blog/cve-2025-53109-53110-escaperoute-anthropic/

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026
