Path Traversal Vulnerability in k6 MCP Server
CVE-2026-89039

6.5MEDIUM

Key Information:

Vendor

Grafana

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-89039?

The k6 MCP server is susceptible to a path traversal vulnerability due to the improper handling of file paths in the convert_playwright_script prompt. When using '@'-prefixed paths, restrictions are enforced to limit file access to the current working directory. However, a bare path can bypass this restriction, granting attackers the ability to read arbitrary files accessible to the server user. This includes sensitive files like SSH private keys, particularly due to the expansion of the '~' character to the user's home directory. Additionally, symbolic links in the working directory allow further exploits, as the path is not canonicalized prior to the restriction's application. All versions from v0.3.0 onwards are affected, highlighting the urgency of applying necessary mitigations.

Affected Version(s)

Mcp K6 0.3.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

bebold6133 (Researcher)
.