Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 30 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, save_agent_history_path, or save_download_path parameters. Attackers can exploit this via the unauthenticated Gradio interface to create directories anywhere the root-running container has write access. | |
| Title | browser-use web-ui 2.0.0 through 3.0.0 Arbitrary Directory Creation | |
| First Time appeared |
Browser-use
Browser-use browser Use |
|
| Weaknesses | CWE-73 | |
| CPEs | cpe:2.3:a:browser-use:browser_use:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Browser-use
Browser-use browser Use |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-30T13:23:37.621Z
Reserved: 2026-08-30T13:05:51.680Z
Link: CVE-2026-82637
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-73
External Control of File Name or Path