GHSA-6fg3-hvw7-2fwq

Suggest an improvement
Source
https://github.com/advisories/GHSA-6fg3-hvw7-2fwq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-6fg3-hvw7-2fwq/GHSA-6fg3-hvw7-2fwq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6fg3-hvw7-2fwq
Aliases
Published
2026-01-07T12:31:25Z
Modified
2026-02-03T03:16:20Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L CVSS Calculator
Summary
Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools
Details

Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victim’s web browser and send unauthorized requests to a locally running MCP server, resulting in unintended invocation of MCP tool endpoints.

Database specific
{
    "cwe_ids":  [
        "CWE-749"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-01-07T20:02:55Z",
    "nvd_published_at":  "2026-01-07T12:17:06Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / @playwright/mcp

Package

Name
@playwright/mcp
View open source insights on deps.dev
Purl
pkg:npm/%40playwright/mcp

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.40

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-6fg3-hvw7-2fwq/GHSA-6fg3-hvw7-2fwq.json"