CVE-2026-89039 | A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that user's home directory (path traversal). The working-directory restriction applied to '@'-prefixed paths can also be bypassed with a symbolic link inside the working directory that points outside it.
A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that user's home directory (path traversal). The working-directory restriction applied to '@'-prefixed paths can also be bypassed with a symbolic link inside the working directory that points outside it.
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-24 | 2026-10-08 |
|---|---|---|
| ≥90 % | 484 | 342 |
| ≥50 % | 1436 | 1061 |
| ≥10 % | 16 | 2 |
| <10 % | 30 | 562 |
CVE-2026-89039 | A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that user's home directory (path traversal). The working-directory restriction applied to '@'-prefixed paths can also be bypassed with a symbolic link inside the working directory that points outside it.
A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud cr
Noch keine Analyse zu CVE-2026-89039
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.