AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T14:17:03.890Z and has not been modified since then. This vulnerability affects browser-use web-ui versions 2.0.0 through 3.0.0, which store configured LLM API keys in cleartext on disk. The vulnerability allows unauthorized access to sensitive API keys, potentially leading to misuse. Security tea [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T14:17:03.470Z and has not been modified since then. The browser-use web-ui versions 2.0.0 through 3.0.0 are vulnerable to arbitrary directory creation via the unauthenticated Gradio interface. This vulnerability can lead to potential directory creation at arbitrary locations where the root-runnin [truncated]