CVE-2026-82637 | browser-use web-ui up to 3.0.0 Gradio interface run_agent_task path traversal
A vulnerability, which was classified as critical, was found in browser-use web-ui up to 3.0.0. The impacted element is the function run_agent_task of the component Gradio interface. The manipulation of the argument save_recording_path/save_trace_path/save_agent_history_path/save_download_path results in path traversal.
This vulnerability is known as CVE-2026-82637. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More