PatchSiren

browser-use CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM browser-use CVE published 2026-08-30

CVE-2026-82640

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T14:17:03.890Z and has not been modified since then. This vulnerability affects browser-use web-ui versions 2.0.0 through 3.0.0, which store configured LLM API keys in cleartext on disk. The vulnerability allows unauthorized access to sensitive API keys, potentially leading to misuse. Security tea [truncated]

MEDIUM browser-use CVE published 2026-08-30

CVE-2026-82637

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T14:17:03.470Z and has not been modified since then. The browser-use web-ui versions 2.0.0 through 3.0.0 are vulnerable to arbitrary directory creation via the unauthenticated Gradio interface. This vulnerability can lead to potential directory creation at arbitrary locations where the root-runnin [truncated]