Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-89039— CVE-2026-89039 CVE Record

Quick assessment

Affected
Grafana Mcp K6
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 k6 MCP 服务器中, 提示(prompt)接受 参数作为文件路径。文档中说明的以“@”为前缀的路径形式被限制在服务器的当前工作目录下,但未经前缀的裸路径会通过另一条未记录的代码路径进行解析,该路径并不施加此类限制。因此,能够调用该提示的用户可以读取服务器运行用户有权读取的任何文件(包括工作目录之外的文件),并将文件内容作为提示响应返回。 路径开头的“~”会被扩展为用户的主目录,因此像 SSH 私钥这样的凭据文件可直接被访问。此外,通过在工作目录内创建指向目录外的符号链接,还可绕过工作目录限制,因为该限制应用

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89039

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CVE-2026-89039 CVE Record
Source: CVE Program / CVE List V5
Vulnerability Description
The convert_playwright_script prompt in the k6 MCP server accepts a file path as its playwright_script argument. Paths given in the documented '@'-prefixed form are restricted to the server's current working directory, but a bare path is resolved by a separate undocumented code path that applies no such restriction. A caller able to invoke the prompt can therefore read any file readable by the user running the server, including files outside the working directory, and receives the file contents in the prompt response. A leading '~' is expanded to the user's home directory, so credential files such as SSH private keys are directly addressable. The working-directory restriction is additionally bypassable through a symbolic link inside the working directory that points outside it, because the path is not canonicalized before the restriction is applied. All releases from v0.3.0 onward are affected; releases v0.3.0 and v0.4.0 apply no restriction to either form.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Grafana Mcp K6 0.3.0 -

II. Public POCs for CVE-2026-89039

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89039

请登录查看更多情报信息。

Other References for CVE-2026-89039 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-89039

No comments yet


Leave a comment