CVE-2025-53109CVE-2025-53110EscapeRoute: Filesystem MCP server sandbox escape
Cymulate found a sandbox escape and a symlink bypass in Anthropic's Filesystem MCP server, letting it reach files outside the directories it was allowed to use.
What happened
Cymulate disclosed two flaws, which it named EscapeRoute, in Anthropic's Filesystem MCP server: a sandbox escape and a symlink bypass, tracked as CVE-2025-53109 and CVE-2025-53110. The server is meant to confine an agent to a list of allowed directories, and both flaws let it step outside them.
Fixes shipped in versions 0.6.4 and 2025.7.01.
Why it worked
The directory restriction depended on the server's own path checks. Once those checks could be fooled, for example by a symbolic link pointing elsewhere, nothing else stopped the process from reading or writing outside the allowed paths.
What to do
- Update the Filesystem MCP server to a fixed release.
- Run file-access servers in a container that mounts only the project directory.
- Don't rely on an MCP server's own allowlist as your only boundary.
- Keep credentials and SSH keys out of any directory an agent can reach.
Sandbox code and tool executionUse least-privilege credentials
mcp-remote OS command injection via authorization_endpoint
Supabase MCP agent leaks tokens through a support ticket
Work through the security checklist →