MEDIUMVulnerability

CVE-2026-82637

browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, save_agent_history_path, or save_download_path parameters. Attackers can exploit this via the unauthenticated Gradio interface to create directories anywhere the root-running container has write access.

Properties

severity
MEDIUM
score
5.3
epss_score
0.0024
cve_id
CVE-2026-82637
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
published_at
2026-08-30T14:17:03.470
last_modified
2026-09-02T18:21:27.743
epss_percentile
0.15018

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]External Control of File Name or Path

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82637 — Ninja Signal Threat Intelligence | Ninja Signal