{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/browse-mcp--0.8.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-55557"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["browse-mcp (\u003c= 0.8.1)"],"_cs_severities":["high"],"_cs_tags":["arbitrary-file-write","path-traversal","rce","agent-security"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe browse-mcp package (versions \u0026lt;= 0.8.1) contains a critical path traversal vulnerability that permits arbitrary file writes on the host machine. This issue arises from the \u003ccode\u003ebrowser_download\u003c/code\u003e, \u003ccode\u003ebrowser_save_state\u003c/code\u003e, and \u003ccode\u003ebrowser_load_state\u003c/code\u003e functions, which fail to validate destination directory paths or file path arguments provided by MCP clients. An attacker operating as a malicious MCP client, or by utilizing indirect prompt injection against an autonomous agent, can specify absolute paths or use directory traversal characters (..) to write arbitrary data to restricted locations, such as bash configuration files, cron entries, or autostart directories. Furthermore, the \u003ccode\u003eforce_fetch\u003c/code\u003e utility was discovered to ignore the \u003ccode\u003eBROWSE_MCP_ALLOWED_ORIGINS\u003c/code\u003e fence, allowing for unauthorized data retrieval. These flaws provide a direct pathway for host code execution. The vulnerability is addressed in browse-mcp version 0.8.2, which introduces path confinement and improved input sanitization.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies an autonomous agent or MCP client environment utilizing browse-mcp.\u003c/li\u003e\n\u003cli\u003eThe attacker triggers an indirect prompt injection by serving a malicious URL to the agent's browser tool.\u003c/li\u003e\n\u003cli\u003eThe agent or malicious client calls the \u003ccode\u003ebrowser_download\u003c/code\u003e or \u003ccode\u003ebrowser_save_state\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe attacker provides a crafted \u003ccode\u003esave_dir\u003c/code\u003e or \u003ccode\u003epath\u003c/code\u003e argument containing directory traversal (e.g., ../../../home/user/.bashrc).\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ebrowser-mcp\u003c/code\u003e service fetches content from the attacker-controlled source or writes provided state data.\u003c/li\u003e\n\u003cli\u003eThe application performs the write operation at the destination path without path validation.\u003c/li\u003e\n\u003cli\u003eThe attacker overwrites a critical configuration file to include malicious commands.\u003c/li\u003e\n\u003cli\u003eUpon file execution or shell initialization, the injected commands run, resulting in full host code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary file write, which can result in full host code execution (HCE). This impacts the security posture of any environment where an autonomous agent utilizes browse-mcp, as it bridges the gap between web-based data retrieval and host filesystem access. There is no indication of mass exploitation, but the vulnerability is highly severe in agentic workflows.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade browse-mcp to version 0.8.2 or higher to implement mandatory path confinement.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately feasible, remove or disable the \u003ccode\u003ebrowser_download\u003c/code\u003e, \u003ccode\u003ebrowser_save_state\u003c/code\u003e, and \u003ccode\u003ebrowser_load_state\u003c/code\u003e tools within the \u003ccode\u003eBROWSE_MCP_TOOLS\u003c/code\u003e configuration.\u003c/li\u003e\n\u003cli\u003eAudit application logs for abnormal path usage or tool calls involving directory traversal patterns (e.g., \u0026quot;..\u0026quot; or absolute paths) when invoking browser management tools.\u003c/li\u003e\n\u003cli\u003eDefine a hardened configuration by strictly controlling the \u003ccode\u003eBROWSE_MCP_HOME\u003c/code\u003e environment variable to ensure all state data is constrained to a known, non-sensitive directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T18:50:18Z","date_published":"2026-08-25T18:50:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-browse-mcp-rce/","summary":"The browse-mcp package is vulnerable to arbitrary file write via unsanitized path arguments in browser tools, allowing an attacker to achieve host code execution by overwriting critical system configuration files.","title":"Arbitrary File Write in browse-mcp Leading to Host Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-08-browse-mcp-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Browse-Mcp (\u003c= 0.8.1)","version":"https://jsonfeed.org/version/1.1"}