Intel

AIKIDO-2025-10386

browser-use is vulnerable to Improper Access Control

Improper Access Control Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 20, 2025

91

Critical Risk

This Affects:

PYTHONbrowser-use
0.2.1 - 0.2.7
Fixed in 0.3.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to domain restriction bypass, allowing prompt injection, unauthorized data access, and exposure of sensitive data. The patch introduces strict domain validation in controller methods, improves test coverage, and updates documentation with security guidelines.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

browser-use is vulnerable to Improper Access Control in versions 0.2.1 - 0.2.7.

How to fix this

Upgrade the browser-use library to the patch version.