CVE-2026-89039
🔶 mediumSummary
A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that user's home directory (path traversal). The working-directory restriction applied to '@'-prefixed paths can also be bypassed with a symbolic link inside the working directory that points outside it.
CVSS Score
6.5
Medium
EPSS Score
0.4
Exploit Probability
Published Date
2026-10-05
First Seen: 2026-10-08
📊 Relative Risk Intelligence
This CVE is Lower Risk - more severe than 46.5% of all 365,616 vulnerabilities in our database.
#195,441
Below average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Oct 5, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Partial
Limited system impact
🏆 Discovered By
bebold6133 (Researcher)
SSVC data provided by
CISA
Last Modified
2026-10-06
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N