Skip to content

Browser Use allows bypassing `allowed_domains` by putting a decoy domain in http auth username portion of a URL

Critical severity GitHub Reviewed Published May 4, 2025 in browser-use/browser-use • Updated May 5, 2025

No open alerts for this advisory

Give feedback on Dependabot alerts