PT-2026-81396 · Unknown · Browse-Mcp
CVSS v4.0
8.6
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
browse-mcp versions prior to 0.8.2
Description
The software contains an arbitrary file write flaw where the
browser download function writes a fetched response body to a path created by join(save dir, filename) without validating the save dir variable. Additionally, the browser save state and browser load state functions honor a caller-controlled path without validation. A malicious MCP client or an autonomous agent influenced by indirect prompt injection can specify an arbitrary save dir or state path and a URL to write attacker-controlled content to any location the process can access, such as ~/.bashrc, autostart entries, or cron files, potentially leading to host code execution. Furthermore, the force fetch fallback uses a raw fetch() function that bypasses the BROWSE MCP ALLOWED ORIGINS origin fence.Recommendations
Update to browse-mcp version 0.8.2.
As a temporary mitigation, restrict the exposed tools using
BROWSE MCP TOOLS to exclude the browser download, browser save state, and browser load state functions.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Browse-Mcp