lowCVSS 6.3Vulnerability

CVE-2026-5327

A security flaw has been discovered in efforthye fast-filesystem-mcp up to 3.5.1. The affected element is the function handleGetDiskUsage of the file src/index.ts. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Properties

summary
fast-filesystem-mcp is vulnerable to command injection through handleGetDiskUsage function
severity
low
epss_score
0.0111
cvss_score
6.3
ghsa_published
2026-04-02T12:31:05Z
source_url
https://github.com/advisories/GHSA-5226-3rvg-hp4x
ghsa_updated
2026-04-04T05:39:07Z
ghsa_id
GHSA-5226-3rvg-hp4x
cve_id
CVE-2026-5327
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.63424

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]npm/fast-filesystem-mcp

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-5327 (CVSS 6.3) — Ninja Signal Threat Intelligence | Ninja Signal