CVE-2025-5273: High severity MCP mcp-markdownify-server vulnerability
All versions of the package mcp-markdownify-server are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a prompt that, once accessed by the MCP host, will allow it to read arbitrary files from the host running the server.
Other sources
Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a prompt that, once accessed by the MCP host, will allow it to read arbitrary files from the host running the server.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mcp-markdownify-serverto a version that resolves this vulnerability.Fixed in 1.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5273?
CVE-2025-5273 is considered a high-severity vulnerability due to its potential for attackers to access arbitrary files on the server.
How do I fix CVE-2025-5273?
To fix CVE-2025-5273, update to the latest version of the mcp-markdownify-server package where this vulnerability has been addressed.
Who is affected by CVE-2025-5273?
All users of the mcp-markdownify-server package, regardless of version, are vulnerable to CVE-2025-5273.
What type of attack can be executed due to CVE-2025-5273?
CVE-2025-5273 allows attackers to perform unauthorized file access, potentially compromising sensitive data on the server.
Is there a workaround for CVE-2025-5273 if I can't upgrade?
If an upgrade is not immediately possible, restricting access to the get-markdown-file tool and implementing strict file permissions can mitigate exposure to CVE-2025-5273.