Advisories for Npm/Chrome-Devtools-Mcp package

2026

chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots

I originally reported this through Google Bug Hunters. The Google Bug Hunters team said this is in OSS VRP scope but not reward-eligible due to the project tier, and asked me to file an issue or PR directly with this repository. I am reporting it privately here first because it is an unfixed security issue. McpContext.validatePath() enforces workspace roots by checking whether path.resolve(filePath) textually falls under one of the configured …

Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory

The chrome-devtools-mcp daemon writes its PID file with fs.writeFileSync() to a deterministic runtime path. On typical macOS environments, and on Linux sessions where $XDG_RUNTIME_DIR is unset, that runtime path falls back to /tmp/chrome-devtools-mcp-<uid>/daemon.pid. Because the write does not use O_NOFOLLOW, a local low-privilege user on the same POSIX host can pre-create /tmp/chrome-devtools-mcp-<victim_uid>/daemon.pid as a symlink to a file writable by the victim. When the victim later starts daemon mode, fs.writeFileSync() …