PatchSiren

That1Drifter CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH That1Drifter CVE published 2026-08-25

CVE-2026-55557

CVE-2026-55557 is a high-severity vulnerability in the browse-mcp server, a Playwright-based headless-browser MCP server for MCP-capable agents. The vulnerability allows a malicious MCP client or an autonomous agent to write arbitrary file contents to any path the process can reach, potentially leading to host code execution. This issue arises from the lack of validation of the caller-controlled save_dir [truncated]