Home
MEDIUM: 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:NDefault status
unaffected
Any version before 0.1.45
affected
Description
In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.
Problem types
CWE-647 Use of Non-Canonical URL Paths for Authorization Decisions
Product status
Any version before 0.1.45
References
github.com/...er-use/security/advisories/GHSA-x39x-9qw5-ghrf
github.com/browser-use/browser-use/releases/tag/0.1.45
github.com/browser-use/browser-use/pull/1561