PT-2026-106004 · Grafana · Mcp K6

·

CVE-2026-89039

·

Publicado

2026-10-05

·

Atualizado

2026-10-05

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
A caller who can invoke the convert playwright script prompt in mcp-k6 can pass a bare file path as the playwright script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that user's home directory (path traversal). The working-directory restriction applied to '@'-prefixed paths can also be bypassed with a symbolic link inside the working directory that points outside it.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-89039

Produtos afetados

Mcp K6