Sceawere
Vulnerability Detail
CVE-2026-89039UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
k6 MCP Arbitrary File Read
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 4h ago
- Vendor
- Grafana
- Product
- mcp-k6
- Attack Type
- CWE-22
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The convert_playwright_script prompt in the k6 MCP server accepts a file path as its playwright_script argument. Paths given in the documented '@'-prefixed form are restricted to the server's current working directory, but a bare path is resolved by a separate undocumented code path that applies no such restriction. A caller able to invoke the prompt can therefore read any file readable by the user running the server, including files outside the working directory, and receives the file contents in the prompt response. A leading '~' is expanded to the user's home directory, so credential files such as SSH private keys are directly addressable. The working-directory restriction is additionally bypassable through a symbolic link inside the working directory that points outside it, because the path is not canonicalized before the restriction is applied. All releases from v0.3.0 onward are affected; releases v0.3.0 and v0.4.0 apply no restriction to either form.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-05T15:17:23.130Z",
"pubdate": "2026-10-05T15:17:23.130Z",
"executiveSummary": "The k6 MCP server contains an Arbitrary File Read vulnerability within the convert_playwright_script prompt handler. This security flaw stems from insufficient input validation and inconsistent path handling logic.\nAn attacker capable of invoking the prompt can bypass intended path restrictions to access sensitive files outside of the server's designated working directory, including system configuration files and user credentials.\nThe vulnerability affects all releases starting from v0.3.0. Versions v0.3.0 and v0.4.0 lack all path restrictions, while subsequent versions fail to prevent access via bare paths or symlink-based directory traversal.\nSuccessful exploitation allows unauthorized retrieval of arbitrary file contents, potentially leading to full system compromise if sensitive secrets such as SSH private keys are exfiltrated. The attack requires no authentication beyond access to the MCP server's prompt interface.",
"technicalDetails": "The vulnerability resides in the path resolution logic of the convert_playwright_script prompt. The system utilizes two distinct methods for processing the playwright_script file path argument, creating a security disparity.\nThe primary, documented path resolution method enforces a restriction to the current working directory using an '@'-prefixed notation. However, a secondary, undocumented code path handles bare paths without applying the same restrictive checks. This bypass allows an attacker to access any file readable by the OS user executing the k6 MCP server process.\nThe input handling logic expands leading tilde ('~') characters to the user's home directory, directly exposing high-value targets such as ~/.ssh/id_rsa or other configuration files containing authentication material.\nFurthermore, the directory restriction mechanism is flawed due to a lack of canonicalization. An attacker can circumvent the working directory boundary by placing a symbolic link within the restricted directory that points to a target outside of it. The server follows these symlinks without verifying that the resolved target resides within the authorized file system scope.\nThe exploitation flow is as follows: 1) An attacker invokes the convert_playwright_script prompt via the MCP interface. 2) The attacker provides a target file path (either a path prefixed with '~' or a path resolved via a symlink) as the playwright_script argument. 3) The server's undocumented resolution logic fails to perform boundary validation or canonicalization. 4) The server reads the content of the specified file. 5) The server returns the file contents directly to the attacker in the prompt response.\nThis vulnerability is present in k6 MCP server v0.3.0 and all subsequent releases. Versions v0.3.0 and v0.4.0 are particularly vulnerable as they omit even the '@'-prefixed path restrictions, whereas later versions maintain the flaw through the undocumented path traversal vector.\nThe impact is significant, as it facilitates unauthorized information disclosure of sensitive local files, which serves as a critical primitive for further lateral movement or privilege escalation within the host environment."
}