@angular/cli is vulnerable to Path Traversal
58
Medium Risk
The Angular CLI MCP server's get_best_practices tool resolves and reads a package.json-declared guide file from a caller-supplied workspacePath without checking that path against the MCP client's authorized workspace roots, unlike other workspace-path-consuming tools on the same server. A caller that can invoke the tool can point it at unintended locations on disk and read content outside the authorized project directories. The fix enforces the same isAllowedWorkspacePath root check used elsewhere and throws when the supplied path falls outside the authorized roots.
You are affected if you are using a version that falls within the vulnerable range and run the Angular CLI MCP server (ng mcp) with a client that can supply a workspacePath outside your authorized project directories.
@angular/cli is vulnerable to Path Traversal in versions 21.0.0 - 22.1.4.
Upgrade the @angular/cli library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.