In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.
Metrics
Affected Vendors & Products
References
History
Mon, 05 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 03 May 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-647 | |
Metrics |
cvssV3_1
|
Sat, 03 May 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-05-03T00:00:00.000Z
Updated: 2025-05-05T15:46:45.254Z
Reserved: 2025-05-03T00:00:00.000Z
Link: CVE-2025-47241

Updated: 2025-05-05T15:44:31.101Z

Status : Awaiting Analysis
Published: 2025-05-03T21:15:48.023
Modified: 2025-05-05T20:54:19.760
Link: CVE-2025-47241

No data.