camofox-mcp@1.0.0

Anti-detection browser MCP server for AI agents — navigate, interact, and automate the web without getting blocked

  • latest version

    1.15.0

  • latest non vulnerable version

  • first published

    6 months ago

  • latest version published

    10 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the camofox-mcp package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Missing Authentication for Critical Function

    camofox-mcp is an Anti-detection browser MCP server for AI agents — navigate, interact, and automate the web without getting blocked

    Affected versions of this package are vulnerable to Missing Authentication for Critical Function through the /mcp handler in src/http.ts. An attacker can list and invoke browser-control tools by sending requests to the MCP endpoint without any inbound API key or authorization header. When HTTP mode is exposed beyond local loopback bind, the server accepts those requests and forwards the resulting tool calls to the backend browser service using the server-side CAMOFOX_API_KEY if configured. This allows an unauthenticated client to drive browser actions such as tab creation, navigation, and interactions with authenticated browser contexts, undermining the intended control plane for anyone who can reach /mcp.

    How to fix Missing Authentication for Critical Function?

    Upgrade camofox-mcp to version 1.13.2 or higher.

    <1.13.2