CVE-2026-27735 | modelcontextprotocol servers up to 2026.1.13 repo.index.add files path traversal (EUVD-2026-8770)
A vulnerability was found in modelcontextprotocol servers up to 2026.1.13 and classified as critical. This impacts the function repo.index.add. The manipulation of the argument files results in path traversal.
This vulnerability is reported as CVE-2026-27735. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.