VYPR

firecrawl-mcp-server

by Mendableai

CVEs (1)

  • CVE-2026-85606HigSep 4, 2026
    risk 0.49cvss 7.5epss

    firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply absolute paths or directory traversal sequences to read…