CVE-2026-53765 | ChromeDevTools chrome-devtools-mcp up to 1.0.x on Linux PID File daemon.pid fs.writeFileSync XDG_RUNTIME_DIR link following (GHSA-3pvj-jv98-qhjq)

SecurityVulns

A vulnerability described as critical has been identified in ChromeDevTools chrome-devtools-mcp up to 1.0.x on Linux. This impacts the function fs.writeFileSync of the file /tmp/chrome-devtools-mcp-/daemon.pid of the component PID File Handler. The manipulation of the argument XDG_RUNTIME_DIR results in link following.

This vulnerability is reported as CVE-2026-53765. The attack requires a local approach. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More