dotsagent.io
Language:English
CVE-2025-53109CVE-2025-53110

EscapeRoute: Filesystem MCP server sandbox escape

Cymulate found a sandbox escape and a symlink bypass in Anthropic's Filesystem MCP server, letting it reach files outside the directories it was allowed to use.

What happened

Cymulate disclosed two flaws, which it named EscapeRoute, in Anthropic's Filesystem MCP server: a sandbox escape and a symlink bypass, tracked as CVE-2025-53109 and CVE-2025-53110. The server is meant to confine an agent to a list of allowed directories, and both flaws let it step outside them.

Fixes shipped in versions 0.6.4 and 2025.7.01.

Why it worked

The directory restriction depended on the server's own path checks. Once those checks could be fooled, for example by a symbolic link pointing elsewhere, nothing else stopped the process from reading or writing outside the allowed paths.

What to do

  • Update the Filesystem MCP server to a fixed release.
  • Run file-access servers in a container that mounts only the project directory.
  • Don't rely on an MCP server's own allowlist as your only boundary.
  • Keep credentials and SSH keys out of any directory an agent can reach.

Sandbox code and tool executionUse least-privilege credentials

Work through the security checklist →

Sources

  1. cymulate.com/blog/cve-2025-53109-53110-escaperoute-anthropic/

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026