VYPR

Web UI

by Browser Use

CVEs (2)

  • CVE-2026-82640MedAug 30, 2026
    risk 0.36cvss 5.5epss

    browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.

  • CVE-2026-82637MedAug 30, 2026
    risk 0.34cvss 5.3epss

    browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, save_agent_history_path, or…