Skip to content
Dev.to1 min read

Arbitrary JavaScript Execution via eval() in...

Arbitrary JavaScript Execution via eval() in chrome-local-mcp Severity: Critical | CWE: CWE-94 (Code Injection) | Package: chrome-local-mcp v1.3.0 We found a critical vulnerability in chrome-local-mcp, a popular MCP server that gives AI agents like Claude full browser control through Puppeteer. The issue is straightforward: an eval tool passes user-supplied JavaScript directly to the browser with zero restrictions. Combined with persistent login sessions, this turns any prompt injection into cre
Read original on dev.to
0
0

Comment

Sign in to join the discussion.

Loading comments…

Related

Get the 10 best reads every Sunday

Curated by AI, voted by readers. Free forever.

Liked this? Start your own feed.

0
0