CVE-2026-102878
Received Received - Intake

Origin Validation Flaw in mcp-chrome-bridge Allows CORS Bypass

Vulnerability report for CVE-2026-102878, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hangwin mcp-chrome-bridge to 1.0.31 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

mcp-chrome-bridge through version 1.0.31 has an origin validation error in its native-server HTTP API that allows bypassing CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server, enabling script execution, page content reading, and screenshot capture.

Detection Guidance

To detect this vulnerability, check if your mcp-chrome-bridge server is running and accessible on localhost. Look for unexpected cross-origin requests to local ports. Use tools like curl to test CORS headers: curl -H 'Origin: http://127.0.0.1.evil.com' -I http://localhost:port. Monitor browser developer tools for unauthorized script execution or page content access.

Impact Analysis

An attacker can trick you into visiting a malicious page that interacts with your local mcp-chrome-bridge server. This could allow them to control your browser automation tools, access sensitive data like page content, execute scripts, or capture screenshots without your knowledge.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data (e.g., page content, screenshots), potentially violating GDPR's data protection principles or HIPAA's confidentiality requirements. Unauthorized access to user data may result in compliance breaches depending on the context of use.

Mitigation Strategies

Immediately update mcp-chrome-bridge to the latest version beyond 1.0.31. If updating is not possible, disable the native-server HTTP API or restrict access to localhost only. Add strict origin validation in SERVER_CONFIG.CORS_ORIGIN to prevent wildcard or prefix-based matches. Block external domains from making requests to local ports.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102878. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart