THREAT OPS › Threat News › [GHSA] GHSA-8qf9-62x2-82pp (medium) — chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
[GHSA] GHSA-8qf9-62x2-82pp (medium) — chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
GHSA-8qf9-62x2-82pp Severity: medium CVE: CVE-2026-53766
chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
### Summary
I originally reported this through Google Bug Hunters. The Google Bug Hunters team said this is in OSS VRP scope but not reward-eligible due to the project tier, and asked me to file an issue or PR directly with this repository. I am repo
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-53766cve
Original source: https://github.com/advisories/GHSA-8qf9-62x2-82pp