Executive brief
chrome-devtools-mcp is a developer tool that manages workspace file access for Chrome DevTools interactions. The validatePath() function fails to canonicalize symlinks before checking workspace boundaries, allowing an attacker to read or write files outside the configured workspace root through symlinks. This can expose sensitive files like cloud credentials, SSH keys, or API tokens, or allow overwrites to critical system files.
Technical details
The vulnerability is a path canonicalization bypass in McpContext.validatePath() (src/McpContext.ts:178-199). The function uses path.resolve() to normalize paths, which only handles relative path notation (. and ..) but does not resolve symbolic links. A relative symlink within the workspace can therefore pass the textual prefix check against configured roots and then be followed during actual filesystem operations (fs.writeFile, fs.mkdir, puppeteer.uploadFile). The attack requires a symlink to exist inside the workspace pointing outside it; this can occur from local workspace state or be created by a malicious workflow. The fix is to use fs.realpath() to canonicalize paths before validation. Versions 0.24.0 through 1.0.1 are affected; patch available in 1.1.0.
Affected products
- ChromeDevTools chrome-devtools-mcp 0.24.0 through 1.0.1
Timeline
- 2026-06-16: disclosed: GitHub Advisory published
- 2026-06-16: patched: Patch version 1.1.0 released
- 2026-08-17: advisory: CVE-2026-53766 assigned