CVE-2026-89039
Received Received - Intake

Path Traversal in k6 MCP Server

Vulnerability report for CVE-2026-89039, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Grafana Labs

Description

The convert_playwright_script prompt in the k6 MCP server accepts a file path as its playwright_script argument. Paths given in the documented '@'-prefixed form are restricted to the server's current working directory, but a bare path is resolved by a separate undocumented code path that applies no such restriction. A caller able to invoke the prompt can therefore read any file readable by the user running the server, including files outside the working directory, and receives the file contents in the prompt response. A leading '~' is expanded to the user's home directory, so credential files such as SSH private keys are directly addressable. The working-directory restriction is additionally bypassable through a symbolic link inside the working directory that points outside it, because the path is not canonicalized before the restriction is applied. All releases from v0.3.0 onward are affected; releases v0.3.0 and v0.4.0 apply no restriction to either form.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Grafana Mcp K6 0.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-424 The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker to read any file on the system that the user running the server can access. It occurs because the k6 MCP server's convert_playwright_script prompt has two code paths for handling file paths. One path restricts paths to the server's working directory, but the other does not. Attackers can bypass restrictions by using bare paths or symbolic links to access files outside the working directory, including sensitive files like SSH private keys.

Detection Guidance

This vulnerability can be detected by checking if the k6 MCP server is running and if the convert_playwright_script prompt is exposed. Review server logs for unusual file read requests or responses containing file contents outside the working directory. No specific commands are provided in the context.

Impact Analysis

If you run the k6 MCP server, an attacker with access to the convert_playwright_script prompt could steal sensitive files, such as configuration files, credentials, or private keys. This could lead to unauthorized access to systems, data breaches, or further attacks on your infrastructure.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles or HIPAA's security requirements. Organizations may face fines, legal penalties, or reputational damage if such a breach occurs due to inadequate file access controls.

Mitigation Strategies

Immediately upgrade to a patched version of the k6 MCP server if available. Restrict access to the convert_playwright_script prompt to trusted users only. Disable the prompt if not required. Review file permissions to ensure sensitive files are not readable by the server user.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89039. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart