GHSA-m9mq-7m7q-xc6p

Suggest an improvement
Source
https://github.com/advisories/GHSA-m9mq-7m7q-xc6p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-m9mq-7m7q-xc6p/GHSA-m9mq-7m7q-xc6p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m9mq-7m7q-xc6p
Aliases
Published
2026-08-25T16:28:32Z
Modified
2026-08-26T00:05:58Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
browse-mcp has an arbitrary file write via unconfined download and state paths
Details

Impact

browser_download wrote a fetched file to join(save_dir, filename) with no validation of save_dir, and browser_save_state / browser_load_state honored an explicit path unchanged. The MCP caller controls these arguments (a malicious MCP client, or an autonomous agent steered by indirect prompt injection on a visited page), so an attacker could supply an arbitrary save_dir (or state path) together with a URL whose response body became the file contents, writing attacker-controlled bytes to any path the process can reach (for example ~/.bashrc, an autostart entry, or a cron file). That is an arbitrary file write that can lead to host code execution. The force_fetch fallback additionally used a raw fetch() that bypassed the BROWSE_MCP_ALLOWED_ORIGINS origin fence.

Estimated severity: CVSS 3.1 around 7.8 (High) for the local / agent-mediated case.

Patches

Fixed in 0.8.2. save_dir is confined under the download root (~/.browse-mcp/downloads) and the explicit state path under ~/.browse-mcp/state; absolute paths and .. escapes are rejected, and download filenames are reduced to a bare basename. force_fetch now also honors the origin fence. Data roots remain relocatable via BROWSE_MCP_HOME. Upgrade to browse-mcp 0.8.2.

Workarounds

Restrict the exposed tools with BROWSE_MCP_TOOLS to a set that excludes browser_download, browser_save_state, and browser_load_state (for example the hardened recipe in SECURITY.md). Note that the allowlist hides the tools from an agent but does not stop a malicious MCP client from calling them by name, so upgrading is the real fix.

  • Reported privately by novice-22.
Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-25T16:28:32Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / browse-mcp

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.8.2

Database specific

last_known_affected_version_range
"<= 0.8.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-m9mq-7m7q-xc6p/GHSA-m9mq-7m7q-xc6p.json"