Skip to main content

CVE detail

CVE-2025-47241

In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.

CVSS 4.0 · Medium