Impact
The convert_playwright_script prompt in the k6 MCP server accepts a file path as its playwright_script argument. Documented paths prefixed with '@' are restricted to the server's current working directory, but a bare path is resolved by a separate undocumented code path that applies no such restriction. An attacker able to invoke the prompt can read any file readable by the user running the server, including sensitive credential files such as SSH private keys. This flaw corresponds to path traversal (CWE-22) and script interpretation (CWE-424), leading to unauthorized information disclosure.
Affected Systems
This vulnerability affects Grafana’s k6 MCP server. All releases from version 0.3.0 onward are impacted, with releases 0.3.0 and 0.4.0 applying no restriction on either path form. The affected component is the convert_playwright_script prompt within the k6 MCP server.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Because the prompt can be invoked by any user with access to the server’s interface or API, the attack vector can be remote or local depending on user reach. Exploitation requires only the ability to supply a file path to the prompt; the code path bypasses permission checks, making the vulnerability readily exploitable by attackers who can reach the prompt.
OpenCVE Enrichment