PT-2026-52106 · Unknown · Chrome-Devtools-Mcp
CVE-2026-53766
·
Published
2026-06-24
·
Updated
2026-08-17
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
chrome-devtools-mcp versions 0.24.0 through 1.0.9
Description
A workspace-boundary bypass exists because the
McpContext.validatePath() function fails to canonicalize symbolic links when checking if a path falls under configured root paths. This allows a symbolic link located within a workspace root to point to a file outside that root and still pass validation. Consequently, tools that write to filePath can overwrite files outside the intended root, and the upload file function can read files from outside the root and send them to the active web page.Recommendations
Update to version 1.1.0.
Exploit
Fix
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Chrome-Devtools-Mcp