SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82640

MEDIUM · CVSS 5.5 EPSS 0.06% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-30 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Versions 2.0.0 through 3.0.0 of the browser-use web-ui are vulnerable as they store configured LLM API keys in cleartext within the temporary settings directory, allowing unauthorized access to sensitive information. This exposure could lead to unauthorized use of the API keys, potentially compromising the associated services. Organizations using these versions should prioritize remediation to protect their API credentials from potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82640
Severity
MEDIUM
CVSS
5.5
EPSS
0.06%

Original NVD Description

browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.