
CVE-2026-53765: chrome-devtools-mcp agent DevTools daemon PID write follows symlinks in /tmp fallback runtime dir The advisory describes a symlink-following risk in chrome-devtools-mcp: when $XDGRUNTIMEDIR is unset, the daemon writes http://daemon.pid to a deterministic /tmp-based path via fs.writeFileSync(), so an attacker who can pre-place a symlink at that path may redirect the PID write. #AgentSecurity #LLMSecurity #AISecurity #Advisory https://github.com/advisories/GHSA-3pvj-jv98-qhjq
Post summary
The advisory identifies a symlink‑following vulnerability in chrome-devtools-mcp that could allow an attacker to redirect daemon PID writes via a pre‑placed symlink; no PoC, exploit code, or patch is mentioned.
