{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3afirecrawlfirecrawl-mcp-server3.20.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:firecrawl:firecrawl-mcp-server:3.20.2:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85606"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["firecrawl-mcp-server (3.20.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Firecrawl"],"content_html":"\u003cp\u003eThe firecrawl-mcp-server application, specifically version 3.20.2, contains a critical security flaw in the firecrawl_parse tool. This tool accepts user-provided filePath arguments without performing adequate directory containment validation. An attacker can exploit this lack of sanitization by providing absolute file paths or directory traversal sequences (e.g., ../../../etc/passwd).\u003c/p\u003e\n\u003cp\u003eWhen processed by the MCP server, the application reads the specified file and returns its content to the calling model context. This allows unauthorized actors to exfiltrate sensitive local files, including configuration files, environment variables containing API keys, and system credentials, from the host environment where the MCP server is deployed. Because these servers are often integrated into AI orchestration workflows, successful exploitation directly exposes the underlying environment's secrets to the language model and its users.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to the unauthorized disclosure of sensitive system files and credentials. This could result in the compromise of secondary services if environment variables or private keys are exposed, potentially leading to privilege escalation, lateral movement, or complete host takeover depending on the privileges granted to the user running the MCP server process.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and platform engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all deployments of firecrawl-mcp-server for version 3.20.2 and update to a patched version once available.\u003c/li\u003e\n\u003cli\u003eImplement strict filesystem sandboxing for the MCP server instance, such as running the application in a restricted container with a read-only root filesystem and restricted access to sensitive paths.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the MCP server to authorized users or service accounts only.\u003c/li\u003e\n\u003cli\u003eMonitor application logs for anomalous file read requests or unexpected patterns in filePath parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:27:34Z","date_published":"2026-09-04T15:27:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-firecrawl-mcp-server-lfr/","summary":"The firecrawl-mcp-server version 3.20.2 is vulnerable to arbitrary local file read attacks because the firecrawl_parse tool fails to validate directory containment for the filePath argument.","title":"Arbitrary Local File Read Vulnerability in firecrawl-mcp-server","url":"https://feed.craftedsignal.io/briefs/2026-09-firecrawl-mcp-server-lfr/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:firecrawl:firecrawl-Mcp-Server:3.20.2:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}