{"data":{"id":"d7f49b60-21c0-4903-aac5-ff94114f9d08","title":"CVE-2026-82637: browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing atta","summary":"A vulnerability in browser-use web-ui versions 2.0.0 through 3.0.0 fails to validate file paths in the run_agent_task function, allowing attackers to create directories anywhere on a system by providing absolute paths (full file locations starting from the root) through parameters like save_recording_path. Since the Gradio interface (a web platform for sharing AI tools) doesn't require authentication, attackers can exploit this without logging in.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82637","publishedAt":"2026-08-30T14:17:03.470Z","cveId":"CVE-2026-82637","cweIds":["CWE-73"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["browser-use"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-30T14:17:03.470Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","availability"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}