CPE
The firecrawl-mcp-server version 3.20.2 is vulnerable to arbitrary local file read attacks because the firecrawl_parse tool fails to validate directory containment for the filePath argument.