Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-85606

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Sep 04, 2026
Vendor unknown

Description

firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply absolute paths or directory traversal sequences to read sensitive files like credentials and environment variables, which are then uploaded and returned to the model context.

References