PT-2026-81396 · Unknown · Browse-Mcp

·

CVE-2026-55557

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions browse-mcp versions prior to 0.8.2
Description The software contains an arbitrary file write flaw where the browser download function writes a fetched response body to a path created by join(save dir, filename) without validating the save dir variable. Additionally, the browser save state and browser load state functions honor a caller-controlled path without validation. A malicious MCP client or an autonomous agent influenced by indirect prompt injection can specify an arbitrary save dir or state path and a URL to write attacker-controlled content to any location the process can access, such as ~/.bashrc, autostart entries, or cron files, potentially leading to host code execution. Furthermore, the force fetch fallback uses a raw fetch() function that bypasses the BROWSE MCP ALLOWED ORIGINS origin fence.
Recommendations Update to browse-mcp version 0.8.2. As a temporary mitigation, restrict the exposed tools using BROWSE MCP TOOLS to exclude the browser download, browser save state, and browser load state functions.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55557
GHSA-M9MQ-7M7Q-XC6P

Affected Products

Browse-Mcp