PatchSiren

browserless CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH browserless CVE published 2026-09-16

CVE-2026-92811

CVE-2026-92811 debrief based on the supplied source corpus. The CVE record was published on 2026-09-16T21:17:30.877Z and has not been modified since then. browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary files. This vulnerability allows attackers to navigate Playwright-driven brow [truncated]