CVE-2026-53766Patch(google / chrome-devtools-mcp)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google chrome-devtools-mcp systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforces workspace roots by checking whether path.resolve(filePath) textually falls under one of the configured root paths. path.resolve() does not canonicalize symbolic links. As a result, a symlink inside a configured workspace root can point to a file outside that root, pass validation, and then be followed by downstream file read/write operations. This bypass applies even when the MCP client correctly declares the roots capability with a non-empty list. It is separate from the documented legacy behavior where missing roots capability allows all paths. The practical impact is a workspace-boundary bypass. In the write direction, filePath-writing tools can overwrite out-of-root files through an in-root symlink. In the read direction, upload_file can read through the symlink and send the file to the currently selected web page. This vulnerability is fixed in 1.1.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-59

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome-devtools-mcp

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
chrome-devtools-mcp

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-20: 1Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-20: 108-20
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • HOL@HashgraphOnline
    Patch

    chrome-devtools-mcp 0.24.0-1.0.1: validatePath() enforces workspace roots with path.resolve(), which does not resolve symlinks. A symlink inside an allowed root can point to ~/.ssh or .env, and reads pass validation. Update to 1.1.0. CVE-2026-53766 https://hol.org/guard/security/cves/CVE-2026-53766-chrome-devtools-mcp-validatepath-does-not

    Post summary

    A CVE‑2026‑53766 flaw in chrome‑devtools‑mcp allows symlink traversal to read sensitive files; the issue is fixed in update 1.1.0.

    1501801.4K
    19.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome-devtools-mcp-node.js-

Explore more