PT-2026-2278 · Unknown · Zen Mcp Server

Published

2026-01-12

·

Updated

2026-01-12

·

CVE-2025-66689

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zen MCP Server versions prior to 9.8.2
Description A path traversal issue exists that allows authenticated attackers to read arbitrary files on the system. The issue is due to flawed logic in the is dangerous path() validation function, which uses exact string matching against a blacklist of system directories. Attackers can bypass these restrictions by accessing subdirectories of blacklisted paths.
Recommendations Update Zen MCP Server to version 9.8.2 or later.

Exploit

Fix

Files Accessible to External Parties

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-66689

Affected Products

Zen Mcp Server