CVE-2026-82640: browser-use web-ui 2.0.0 through 3.0.0 Cleartext API Key Storage

Published Aug 30, 2026
·
Updated

browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.

Affected Software

1 affected component
browser-use web-ui>=2.0.0<=3.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade browser-use web-ui to a version that resolves this vulnerability.

    Fixed in 2.0.0 through 3.0.0
  2. Compensating control

    Because browser-use web-ui (versions 2.0.0 through 3.0.0) writes configured LLM API keys to disk in cleartext with no encryption or access restrictions, restrict read access to the temporary settings directory so attackers cannot read predictably-named JSON files containing provider API keys.

Event History

Aug 30, 2026
CVE Published
via MITRE·01:23 PM
Data Sourced
via MITRE·01:23 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments of browser-use web-ui versions 2.0.0 through 3.0.0 are exposed if LLM API keys are configured and an attacker can read the temporary settings directory.

2

What does an attacker need to recover an API key?

The attacker needs local read access to the temporary settings directory. The keys are stored in predictably named JSON files in cleartext, so no decryption is required.

3

How can I determine whether keys may already be exposed?

Check whether an affected browser-use web-ui version wrote configured provider API keys into JSON files in its temporary settings directory, and review which users or processes had read access to that directory.

4

What can be done if updating is not immediately possible?

Restrict read access to the temporary settings directory and treat any keys stored there as potentially exposed. Rotate configured provider API keys if unauthorized read access may have occurred.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203