High severity8.1NVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026
CVE-2026-102878
CVE-2026-102878
Description
mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.0.31
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.