Arbitrary File Write Vulnerability in browse-mcp by That1Drifter
CVE-2026-55557

8.6HIGH

Key Information:

Vendor
CVE Published:
25 August 2026

What is CVE-2026-55557?

The browse-mcp is a headless-browser MCP server that allows the execution of malicious commands due to improper validation of file paths. Versions prior to 0.8.2 are susceptible to exploitation where an attacker can manipulate the save directory or state path, potentially allowing the attacker to write files to arbitrary locations on the system. This severe issue arises from the lack of validation in the browser_download operation and inadequate handling in browser_save_state and browser_load_state functions. In addition, the implementation of raw fetches bypasses origin restrictions, exposing the system to further risks. It is crucial for users to update to version 0.8.2 to mitigate these vulnerabilities.

Affected Version(s)

browse-mcp < 0.8.2

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.