PT-2026-83557 · Unknown · Browser-Use Web-Ui

·

CVE-2026-82637

·

Published

2026-08-30

·

Updated

2026-09-02

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions browser-use web-ui versions 2.0.0 through 3.0.0
Description The software fails to validate browser settings paths within the run agent task() function. This allows unauthenticated users to create directories at arbitrary locations on the system where the root-running container has write access. This is achieved by providing absolute paths to the save recording path, save trace path, save agent history path, or save download path parameters via the Gradio interface.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82637

Affected Products

Browser-Use Web-Ui