CVE-2025-47241: Browser-Use

Medium severity, CVSS 4.0. EPSS: 0.5% chance of exploitation in the next 30 days.

In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.

Affected products

  • Browser-Use Browser-Use: before 0.1.45 (fixed in 0.1.45)

Published 2025-05-03. Last modified 2026-06-17.