CVE-2026-55557: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in That1Drifter browse-mcp
Description
CVE-2026-55557 is a path traversal vulnerability in That1Drifter's browse-mcp server prior to version 0.8.2. The flaw allows an attacker to write arbitrary files to the host filesystem by controlling the save directory and file contents. This can lead to overwriting critical files such as ~/.bashrc, autostart entries, or cron files, potentially enabling code execution on the host. The vulnerability arises from insufficient validation of caller-controlled paths and a fetch fallback that bypasses origin restrictions. The issue is fixed in version 0.8.2.
CVSS v4.0
Score 8.6high
Affected software
That1Drifter
browse-mcp
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The browse-mcp server, a Playwright-based headless-browser MCP server, improperly limits pathname access when writing fetched response bodies to disk. Specifically, before version 0.8.2, the browser_download function writes to a path constructed from a caller-controlled save_dir and filename without validating the save_dir. Additionally, browser_save_state and browser_load_state accept caller-controlled paths without validation. An attacker controlling an MCP client or indirectly influencing an autonomous agent can specify arbitrary paths and URLs, causing attacker-controlled file writes anywhere the process has access, including sensitive configuration files. The force_fetch fallback uses a raw fetch() call that bypasses the BROWSE_MCP_ALLOWED_ORIGINS origin fence, increasing the attack surface. This vulnerability is addressed in browse-mcp version 0.8.2.
Potential Impact
An attacker can write arbitrary files to the host filesystem with the privileges of the browse-mcp process. This includes overwriting critical files such as user shell configuration files (~/.bashrc), autostart entries, or cron jobs, which may lead to remote code execution on the host. The vulnerability does not require user interaction or privileges and can be exploited by a malicious MCP client or through indirect prompt injection influencing an autonomous agent. The origin restriction bypass further facilitates exploitation by allowing fetches from unauthorized origins.
Mitigation Recommendations
A fix is available in browse-mcp version 0.8.2. Users should upgrade to version 0.8.2 or later to remediate this vulnerability. No other mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-16T23:11:20.213Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8dc505acd9273b4972ab4c
Added to database: 08/25/2026, 16:38:29 UTC
Last enriched: 09/10/2026, 03:37:31 UTC
Last updated: 10/09/2026, 18:48:21 UTC
Views: 89
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.