CVE-2026-82640

browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-30 14:17

Updated : 2026-09-10 15:53


NVD link : CVE-2026-82640

Mitre link : CVE-2026-82640

CVE.ORG link : CVE-2026-82640


JSON object : View

Products Affected

No product.

CWE
CWE-312

Cleartext Storage of Sensitive Information