VYPR
Vendor

Browser Use

Products
2
CVEs
3
Across products
3
Status
Private

Products

2

Recent CVEs

3
  • CVE-2026-82640MedAug 30, 2026
    risk 0.29cvss 5.5epss 0.00

    browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.

  • CVE-2026-82637MedAug 30, 2026
    risk 0.27cvss 5.3epss 0.00

    browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, save_agent_history_path, or…

  • CVE-2025-47241MedMay 3, 2025
    risk 0.19cvss 4.0epss 0.00

    In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.