First published: Sat May 03 2025(Updated: )
In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
browser-use browser-use | <0.1.45 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47241 is considered a high severity vulnerability due to the potential for unauthorized access via the mishandling of URL parsing.
To resolve CVE-2025-47241, upgrade to browser-use version 0.1.45 or later to ensure proper URL parsing.
CVE-2025-47241 is a URL parsing vulnerability affecting the allowed_domains configuration.
All users of browser-use versions prior to 0.1.45 are affected by CVE-2025-47241.
As of now, there are no publicly known exploits specifically targeting CVE-2025-47241.