SCA: security update for chrome-devtools-mcp (GHSA-8qf9-62x2-82pp)

medium Tenable Cloud Security Plugin ID 446034

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome
browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforces workspace roots by checking whether
path.resolve(filePath) textually falls under one of the configured root paths. path.resolve() does not
canonicalize symbolic links. As a result, a symlink inside a configured workspace root can point to a file
outside that root, pass validation, and then be followed by downstream file read/write operations. This
bypass applies even when the MCP client correctly declares the roots capability with a non-empty list. It
is separate from the documented legacy behavior where missing roots capability allows all paths. The
practical impact is a workspace-boundary bypass. In the write direction, filePath-writing tools can
overwrite out-of-root files through an in-root symlink. In the read direction, upload_file can read
through the symlink and send the file to the currently selected web page. This vulnerability is fixed in
1.1.0. (CVE-2026-53766)

Solution

Update the chrome-devtools-mcp library and its related packages to version 1.1.0 or later.

See Also

https://github.com/advisories/GHSA-8qf9-62x2-82pp

Plugin Details

Severity: Medium

ID: 446034

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/18/2026

Updated: 8/18/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

Percentile: 96.41

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.2

Temporal Score: 4.1

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:C/A:P

CVSS Score Source: CVE-2026-53766

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/17/2026

Vulnerability Publication Date: 6/24/2026

Reference Information

CVE: CVE-2026-53766