mastergo-design/mastergo-magic-mcp
- <= 0.2.0
A path traversal vulnerability has been identified in the Mastergo-Design Mastergo-Magic-MCP tool, specifically in versions up to 0.2.0. The issue arises within the 'mcp__getComponentGenerator' function, where the 'rootPath' argument is not properly validated. This flaw allows for the creation of directories and files in an attacker-specified location under the '.mastergo/' directory. The vulnerability requires local exploitation, and although it has been publicly disclosed, the project maintainers have not yet addressed it.
Exploitation of this vulnerability allows for arbitrary directory creation and file writing in locations specified by the attacker, under the '.mastergo/' directory. This could be used to overwrite existing files or disrupt normal project operations.
To reproduce this vulnerability, use the 'mcp__getComponentGenerator' tool and provide a crafted 'rootPath' argument that includes directory traversal sequences. This will create a directory structure and files in the specified location, demonstrating the path traversal vulnerability.
Users are advised to update to version 0.2.3 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.