@browserbasehq/mcp
MCP server for AI web browser automation using Browserbase and Stagehand
Installing this server brings 230 third-party packages inside your agent's trust boundary (6 direct). This is attack surface, not a vulnerability count — it does not affect the grade above.
3 packages in this tree run a script at install time.
Findings (1)
- LOW
VULN_KNOWN— MAL-2025-191195: Malicious code in @browserbasehq/mcp (npm). See https://osv.dev/vulnerability/MAL-2025-191195
Embed this badge
[](https://vulnrable.com/mcp/browserbasehq--mcp/) Automated registry-metadata scan; not a code audit. Rescanned on each site deploy.