What happened
Grafana published CVE-2026-89039 (CVSS 6.5, CWE-22/424) on 2026-10-05 for the convert_playwright_script prompt in its k6 MCP server. A bare file path is resolved by a separate undocumented code path that applies no working-directory restriction — unlike the documented '@'-prefixed path form — so the prompt returns the contents of any readable file, including files outside the working directory, with '~' collapsing to the user's home directory. The working-directory restriction is also bypassable via a symlink because paths are not canonicalized.
Why it matters
This is an MCP tool surface directly callable by LLM agents: a prompt-injected agent (reading a malicious repo, email, or web page) or any caller with MCP access can exfiltrate credential files and source from the machine hosting the k6 MCP server, an outcome that defeats the isolation assumptions of agentic coding and test-automation setups.
Attack vector
A caller invokes the documented convert_playwright_script prompt with a bare (non-'@-prefixed) file path instead of the restricted working-directory form. The undocumented bare-path code path does no directory restriction and does not canonicalize before checking, and a leading '~' expands to the user's home directory, so files such as ~/.ssh/id_rsa or cloud credential files are returned verbatim in the prompt response. The '@' restriction is additionally bypassable with a symlink inside the working directory pointing outside it.
Affected systems
Grafana k6 MCP server (mcp-k6) v0.3.0 and later; everyone in that range is affected
Mitigation
Upgrade to a patched release of mcp-k6 per Grafana's advisory (https://grafana.com/security/security-advisories/cve-2026-89039); restrict who can reach the MCP server; do not expose it on untrusted networks.