The critical RCE disclosure is damaging not because the vulnerability is obscure but because it is written into the tool's own documentation. The README describes browser_run_code as accepting 'a JavaScript function containing Playwright code to execute' — the attack surface is the feature description. Any AI agent with access to the MCP server can invoke this tool with a payload, and the server will execute it.
Loading story