Medium severity5.5NVD Advisory· Published Aug 30, 2026
CVE-2026-82640
CVE-2026-82640
Description
browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 2.0.0 - 3.0.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.