CVE-2026-89039

CVE-2026-89039 published: A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that...

View full NVD advisory → ← Back to CVE watch