Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Firecrawl
Firecrawl firecrawl-mcp-server |
|
| Vendors & Products |
Firecrawl
Firecrawl firecrawl-mcp-server |
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply absolute paths or directory traversal sequences to read sensitive files like credentials and environment variables, which are then uploaded and returned to the model context. | |
| Title | firecrawl-mcp-server 3.20.2 Arbitrary Local File Read via filePath | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T14:32:08.494Z
Reserved: 2026-09-04T11:00:28.731Z
Link: CVE-2026-85606
No data.
Status : Received
Published: 2026-09-04T15:17:41.393
Modified: 2026-09-04T15:17:41.393
Link: CVE-2026-85606
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:30:07Z
