Threat Advisory

Chrome DevTools MCP Workspace Boundary Bypass via Symlink

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-53766 with a CVSS score of 6.1 is a CWE-22 and CWE-59 vulnerability affecting chrome-devtools-mcp versions >= 0.24.0, <= 1.0.1 in chrome-devtools-mcp, specifically in the validatePath function which does not canonicalize symlinks before enforcing roots, allowing a local process/user or trusted workflow to create a symlink inside the workspace that points outside the configured workspace root, enabling tools that write to filePath to overwrite files outside the configured workspace root through an in-root symlink, and upload_file can read a file outside the workspace through an in-root symlink and attach it to a file input on the current page. This vulnerability affects versions prior to 1.1.0 of chrome-devtools-mcp and has a severity of Moderate with a CVSS v3.1 chain estimate of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N, impacting integrity, confidentiality, and stealth/auditability.

RECOMMENDATION:

We recommend you to update chrome-devtools-mcp to version 1.1.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-53766 with a CVSS score of 6.1 is a CWE-22 and CWE-59 vulnerability affecting chrome-devtools-mcp versions >= 0.24.0, <= 1.0.1 in chrome-devtools-mcp, specifically in the validatePath function which does not canonicalize symlinks before enforcing roots, allowing a local process/user or trusted workflow to create a symlink inside the workspace that points outside the configured workspace root, enabling tools that write to filePath to overwrite files outside the configured workspace root through an in-root symlink, and upload_file can read a file outside the workspace through an in-root symlink and attach it to a file input on the current page. This vulnerability affects versions prior to 1.1.0 of chrome-devtools-mcp and has a severity of Moderate with a CVSS v3.1 chain estimate of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N, impacting integrity, confidentiality, and stealth/auditability.

RECOMMENDATION:

We recommend you to update chrome-devtools-mcp to version 1.1.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu