Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

browse-mcp Path Traversal and Arbitrary File Write

browse-mcp versions prior to 0.8.2 allow malicious MCP clients or agents manipulated through prompt injection to write arbitrary files to the host system by bypassing path validation in browser_download, browser_save_state, and browser_load_state functions. This vulnerability could enable host code execution through writes to sensitive files like ~/.bashrc or cron configurations.

Disclosed 13 June 2026 · Record updated 13 September 2026

Impact

Arbitrary file write capability allowing potential host code execution through malicious MCP clients or prompt-injection-steered agents

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55557