Arbitrary File Write Vulnerability in browse-mcp by That1Drifter
CVE-2026-55557
8.6HIGH
What is CVE-2026-55557?
The browse-mcp is a headless-browser MCP server that allows the execution of malicious commands due to improper validation of file paths. Versions prior to 0.8.2 are susceptible to exploitation where an attacker can manipulate the save directory or state path, potentially allowing the attacker to write files to arbitrary locations on the system. This severe issue arises from the lack of validation in the browser_download operation and inadequate handling in browser_save_state and browser_load_state functions. In addition, the implementation of raw fetches bypasses origin restrictions, exposing the system to further risks. It is crucial for users to update to version 0.8.2 to mitigate these vulnerabilities.
Affected Version(s)
browse-mcp < 0.8.2
