CVE-2026-82637

browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, save_agent_history_path, or save_download_path parameters. Attackers can exploit this via the unauthenticated Gradio interface to create directories anywhere the root-running container has write access.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-30 14:17

Updated : 2026-09-02 18:21


NVD link : CVE-2026-82637

Mitre link : CVE-2026-82637

CVE.ORG link : CVE-2026-82637


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path