In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.
Metrics
Affected Vendors & Products
References
History
Mon, 05 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 03 May 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-647 | |
| Metrics |
cvssV3_1
|
Sat, 03 May 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-05-03T00:00:00.000Z
Updated: 2025-05-05T15:46:45.254Z
Reserved: 2025-05-03T00:00:00.000Z
Link: CVE-2025-47241
Updated: 2025-05-05T15:44:31.101Z
Status : Awaiting Analysis
Published: 2025-05-03T21:15:48.023
Modified: 2025-05-05T20:54:19.760
Link: CVE-2025-47241
No data.