Arbitrary local file read in firecrawl-mcp-server 3.20.2
firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can read sensitive files like credentials and environment variables.
Disclosed 4 September 2026 · Record updated 13 September 2026
Impact
Attackers can read sensitive files including credentials and environment variables through unconstrained file path arguments, which are then returned to the model context.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-q267-2jg6-m7vc
