HIGH GitHub
CVE-2026-55557
browse-mcp has an arbitrary file write via unconfined download and state paths
### Impact
`browser_download` wrote a fetched file to `join(save_dir, filename)` with no validation of `save_dir`, and `browser_save_state` / `browser_load_state` honored an explicit `path` unchanged. The MCP caller controls these arguments (a malicious MCP client, or an autonomous agent steered by indirect prompt injection on a visited page), so an attacker could supply an arbitrary `save_dir` (or state `path`) together with a URL whose response body became the file contents, writing attacker-c
Affected Products
- npm/browse-mcp <= 0.8.1
References
- https://github.com/advisories/GHSA-m9mq-7m7q-xc6p
- https://github.com/That1Drifter/browse-mcp/security/advisories/GHSA-m9mq-7m7q-xc6p
- https://github.com/That1Drifter/browse-mcp/pull/58
- https://github.com/That1Drifter/browse-mcp/commit/5352a4a56f626254b445bfa07e4bb48c5aad15c1
This high severity vulnerability was published on 2026-08-25 via GitHub. Affected: npm/browse-mcp <= 0.8.1.
vulnfeed aggregates 11954 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.