Loading market data...
← Back to CVE feed

CVE-2026-102878

HIGH CVSS 8.1 View on NVD ↗

Description

mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Published: Sep 29, 2026 20:17 UTC Modified: Sep 29, 2026 21:17 UTC