HIGH
That1Drifter
CVE published 2026-08-25
CVE-2026-55557
CVE-2026-55557 is a high-severity vulnerability in the browse-mcp server, a Playwright-based headless-browser MCP server for MCP-capable agents. The vulnerability allows a malicious MCP client or an autonomous agent to write arbitrary file contents to any path the process can reach, potentially leading to host code execution. This issue arises from the lack of validation of the caller-controlled save_dir [truncated]