browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-30 14:17
Updated : 2026-09-10 15:53
NVD link : CVE-2026-82640
Mitre link : CVE-2026-82640
CVE.ORG link : CVE-2026-82640
JSON object : View
Products Affected
No product.
CWE
CWE-312
Cleartext Storage of Sensitive Information
