目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-89039— 未提供足够信息确定影响软件及类型。

一分钟漏洞结论

影响对象
Grafana Mcp K6
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 k6 MCP 服务器中, 提示(prompt)接受 参数作为文件路径。文档中说明的以“@”为前缀的路径形式被限制在服务器的当前工作目录下,但未经前缀的裸路径会通过另一条未记录的代码路径进行解析,该路径并不施加此类限制。因此,能够调用该提示的用户可以读取服务器运行用户有权读取的任何文件(包括工作目录之外的文件),并将文件内容作为提示响应返回。 路径开头的“~”会被扩展为用户的主目录,因此像 SSH 私钥这样的凭据文件可直接被访问。此外,通过在工作目录内创建指向目录外的符号链接,还可绕过工作目录限制,因为该限制应用

CVSS 6.5 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-89039 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
CVE-2026-89039 CVE Record
来源: CVE Program / CVE List V5
Vulnerability Description
The convert_playwright_script prompt in the k6 MCP server accepts a file path as its playwright_script argument. Paths given in the documented '@'-prefixed form are restricted to the server's current working directory, but a bare path is resolved by a separate undocumented code path that applies no such restriction. A caller able to invoke the prompt can therefore read any file readable by the user running the server, including files outside the working directory, and receives the file contents in the prompt response. A leading '~' is expanded to the user's home directory, so credential files such as SSH private keys are directly addressable. The working-directory restriction is additionally bypassable through a symbolic link inside the working directory that points outside it, because the path is not canonicalized before the restriction is applied. All releases from v0.3.0 onward are affected; releases v0.3.0 and v0.4.0 apply no restriction to either form.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Grafana Mcp K6 0.3.0 -

二、漏洞 CVE-2026-89039 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-89039 的情报信息

请登录查看更多情报信息。

CVE-2026-89039 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-89039

暂无评论


发表评论