30
30
30
30
30
30
30
30
30
30
45
45
30
30
30
Survey of filesystem MCP servers: how the "sandboxed filesystem" boundary is enforced (one breach, four defended-by-design)
Survey finds one filesystem MCP server vulnerable to a symlink-based sandbox escape while four others are defended by design.
A survey of five filesystem MCP servers assessed how each enforces its path-confinement boundary against symlink escapes in recursive directory walkers. The iceener/files-stdio-mcp-server is vulnerable to a read-side sandbox escape. The other four are defended by design or make no confinement claim. The author describes the vulnerability class as small but real.
30
30
30
30
30
30
30
30
30
30
30
30
30
30
45
30
45
45
30
30
45
30
30
45
45