You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: advisories/github-reviewed/2026/04/GHSA-5226-3rvg-hp4x/GHSA-5226-3rvg-hp4x.json
+28-7Lines changed: 28 additions & 7 deletions
Original file line number
Diff line number
Diff line change
@@ -1,11 +1,12 @@
1
1
{
2
2
"schema_version": "1.4.0",
3
3
"id": "GHSA-5226-3rvg-hp4x",
4
-
"modified": "2026-04-02T12:31:05Z",
4
+
"modified": "2026-04-04T05:39:06Z",
5
5
"published": "2026-04-02T12:31:05Z",
6
6
"aliases": [
7
7
"CVE-2026-5327"
8
8
],
9
+
"summary": "fast-filesystem-mcp is vulnerable to command injection through handleGetDiskUsage function",
9
10
"details": "A security flaw has been discovered in efforthye fast-filesystem-mcp up to 3.5.1. The affected element is the function handleGetDiskUsage of the file src/index.ts. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
0 commit comments