EscapeRoute

Breaking the Filesystem Boundary of an MCP Agent

AFFECTED COMPONENT
@modelcontextprotocol/server-filesystem
VULNERABILITIES
CVE-2025-53109, CVE-2025-53110
ASSESSMENT
Critical relevance to agent-to-runtime boundaries

Executive Summary

In July 2025, researchers disclosed two high-severity vulnerabilities in the reference Model Context Protocol (MCP) Filesystem server.

The vulnerabilities allowed filesystem operations to escape their intended directory restrictions through Symlink handling and Path-prefix validation. The vulnerabilities were assigned CVE-2025-53109 and CVE-2025-53110. The affected filesystem server versions were patched in July 2025.

Architectural Significance

MCP is explicitly designed to give AI systems controlled, standardized access to external capabilities. The MCP server was supposed to enforce a strict containment bound (Agent → Allowed Directory), but vulnerabilities in the filesystem enforcement allowed the agent to punch through the boundary into the host OS.

Intended Architecture

The filesystem MCP server provides tools for reading, writing, searching, creating, deleting, and moving files. Its fundamental access model is designed to restrict the server to explicitly allowed directories.

INTENDED CONTAINMENT ARCHITECTURE
AI AGENT
↓
MODEL CONTEXT PROTOCOL (MCP)
↓
FILESYSTEM SERVER
(Allowed Directory Scope)
↓
SANDBOX
project/
├── src/
└── data/

The vulnerabilities demonstrated that this conceptual boundary could be bypassed, allowing the agent to access the entire underlying host.

Vulnerability 1 — Symlink Escape

CVE-2025-53109 involved a path validation bypass through symlink handling.

A symlink inside an allowed directory could point outside that directory. If the filesystem server followed the link without appropriately validating the resolved destination, an operation that appeared to target the allowed directory could actually affect a file elsewhere on the host.

Allowed directory
→
Symlink
→
Sensitive location

The security system validated the apparent path, while the OS ultimately resolved the physical path elsewhere.

Vulnerability 2 — Path Prefix Collision

CVE-2025-53110 involved insufficient path-boundary validation.

A simplistic prefix check can incorrectly treat /allowed/project and /allowed/project-sensitive as belonging to the exact same security boundary. The CVE record specifically describes unintended access where a path's prefix matched an allowed directory.

This is a classic example of string-level validation being mistaken for filesystem-level authorization.

Attack Chain

Researchers demonstrated that the vulnerabilities could be used to escape the intended filesystem scope and, depending on the environment, reach highly sensitive locations. Security analysis of CVE-2025-53109 also describes the possibility of establishing persistence through unauthorized filesystem writes.

THE ESCAPEROUTE CHAIN
AI AGENT
↓
MCP TOOL INVOCATION
↓
Filesystem Operation
↓
Flawed Path Validation
Symlink Manipulation
Prefix Collision
↓
BOUNDARY BYPASS
↓
Unauthorized File Modification
↓
PERSISTENCE / EXECUTION

Analyst Assessment

EscapeRoute demonstrates a profound property of agentic security: The AI model does not have to be compromised for the agent to escape its intended security boundary.

The agent can make a completely legitimate tool call. The vulnerability exists underneath it, exposing three distinct, decoupled security layers:

Layer 1: AI MODEL
"Read this file."
Layer 2: MCP TOOL
"Read /allowed/file"
Layer 3: OPERATING SYSTEM
"Resolve actual filesystem object"

If Layer 2 incorrectly validates the request, the agent implicitly inherits the resulting destructive capability.

Why This Matters for Opsonance

EscapeRoute is particularly relevant to Opsonance because it proves exactly why runtime security cannot terminate at the application or API boundary.

The MCP server believed it was enforcing a filesystem boundary. But the operating system ultimately determined what object was actually accessed. The security architecture therefore needs visibility into the final runtime effect.

An agent may request: read file A

While the runtime actually produces: open → resolve symlink → access file B

Those are materially different security events.

For Opsonance, this reinforces a core principle: Security policy must be evaluated against runtime reality, not merely against the declared intent of an AI tool invocation.

Key Finding

CONCLUSION

EscapeRoute demonstrates that giving an AI agent a constrained tool does not necessarily mean the agent has constrained authority. The effective security boundary is only as strong as the lowest layer enforcing it.

MODEL POLICY → AGENT POLICY → TOOL POLICY → APP POLICY → RUNTIME POLICY → KERNEL ENFORCEMENT

References