CVE-2026-82640: Browser-Use Web-UI
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.
Affected products
- Browser-Use Web-UI: from 2.0.0, up to and including 3.0.0
Published 2026-08-30. Last modified 2026-09-10.