browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, save_agent_history_path, or save_download_path parameters. Attackers can exploit this via the unauthenticated Gradio interface to create directories anywhere the root-running container has write access.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Browser-use web-ui
|
|
| Vendors & Products |
Browser-use web-ui
|
Sun, 30 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, save_agent_history_path, or save_download_path parameters. Attackers can exploit this via the unauthenticated Gradio interface to create directories anywhere the root-running container has write access. | |
| Title | browser-use web-ui 2.0.0 through 3.0.0 Arbitrary Directory Creation | |
| First Time appeared |
Browser-use
Browser-use browser Use |
|
| Weaknesses | CWE-73 | |
| CPEs | cpe:2.3:a:browser-use:browser_use:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Browser-use
Browser-use browser Use |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-30T13:23:37.621Z
Updated: 2026-09-02T17:45:56.903Z
Reserved: 2026-08-30T13:05:51.680Z
Link: CVE-2026-82637
Updated: 2026-09-02T17:45:32.931Z
Status : Deferred
Published: 2026-08-30T14:17:03.470
Modified: 2026-09-02T18:21:27.743
Link: CVE-2026-82637
No data.