<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T10:27:55.288406+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-47241</id>
    <title>CVE-2025-47241</title>
    <updated>2026-10-05T10:27:55.290221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> browser-use</p>
<p>In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-47241"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x39x-9qw5-ghrf</id>
    <title>GHSA-x39x-9qw5-ghrf — Browser Use allows bypassing `allowed_domains` by putting a decoy domain in http auth username portion of a URL</title>
    <updated>2026-10-05T10:27:55.290289+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: browser-use</p>
<p>### Summary  
During a manual source code review, [**ARIMLABS.AI**](https://arimlabs.ai) researchers identified that the `browser_use` module includes an embedded whitelist functionality to restrict URLs that can be visited. This restriction is enforced during agent initialization. However, it was discovered that these measures can be bypassed, leading to severe security implications.</p>
<p>### Details  
**File:** `browser_use/browser/context.py`</p>
<p>The `BrowserContextConfig` class defines an `allowed_domains` list, which is intended to limit accessible domains. This list is checked in the `_is_url_allowed()` method before navigation:</p>
<p>```python
@dataclass
class BrowserContextConfig:
    """
    [STRIPPED]
    """
    cookies_file: str | None = None
    minimum_wait_page_load_time: float = 0.5
    wait_for_network_idle_page_load_time: float = 1
    maximum_wait_page_load_time: float = 5
    wait_between_actions: float = 1</p>
<p>disable_security: bool = True</p>
<p>browser_window_size: BrowserContextWindowSize = field(default_factory=lambda: {'width': 1280, 'height': 1100})
    no_viewport: Optional[bool] = None</p>
<p>save_recording_path: str | None = None
    save_downloads_path: str | None = None
    trace_path: str | None = None
    locale: str | None = None
    user_agent: str = (
        'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36'
    )</p>
<p>highlight_elements: bool = True
    viewport_expansion: int = 50…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x39x-9qw5-ghrf"/>
  </entry>
</feed>
