Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture. | |
| Title | mcp-chrome-bridge through 1.0.31 CORS Origin Bypass | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T20:19:14.663Z
Reserved: 2026-09-29T17:33:19.455Z
Link: CVE-2026-102878
Updated: 2026-09-29T20:19:07.617Z
Status : Received
Published: 2026-09-29T20:17:18.620
Modified: 2026-09-29T21:17:18.297
Link: CVE-2026-102878
No data.
OpenCVE Enrichment
No data.
-
CWE-346
Origin Validation Error