Executive brief
CamoFox MCP, a tool for controlling web browsers via the Model Context Protocol (MCP), failed to require authentication for its HTTP interface. This allows any network-reachable user to remotely control the server's browser, including navigating to pages, creating tabs, and accessing sensitive browser content. If the server was configured with a backend API key, it would automatically use that key to authorize these unauthorized requests, potentially exposing private data or authenticated sessions.
Technical details
The camofox-mcp package exposed a Streamable HTTP MCP endpoint at `/mcp` that lacked inbound authentication checks. While the server used `CAMOFOX_API_KEY` to authenticate its own outbound requests to the browser backend, it did not verify this or any other secret for inbound client requests. An attacker capable of reaching the `/mcp` endpoint (e.g., via network exposure, Docker port forwarding, or SSRF) could list and execute browser-control tools. This allows for unauthorized browser automation, including page navigation and content observation, using the server's configured credentials. The issue was fixed in version 1.13.2 by implementing mandatory Bearer token authentication and loopback Host-header protection.
Affected products
- redf0x1 camofox-mcp < 1.13.2
Timeline
- 2026-05-14: disclosed: Advisory published by vendor
- 2026-05-14: patched: Fix committed to main branch
- 2026-05-19: advisory: GitHub Advisory published