Vulnerability Description
In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/browser-use/browser-use/pull/1561
- https://github.com/browser-use/browser-use/releases/tag/0.1.45
- https://github.com/browser-use/browser-use/security/advisories/GHSA-x39x-9qw5-gh
FAQ
What is CVE-2025-47241?
CVE-2025-47241 is a vulnerability with a CVSS score of 4.0 (MEDIUM). In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.
How severe is CVE-2025-47241?
CVE-2025-47241 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-47241?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.