Command Injection Vulnerability in Browsertrix Affects Webrecorder
CVE-2026-54501

9.4CRITICAL

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-54501?

Browsertrix, a browser-based web archiving service by Webrecorder, contains a vulnerability that allows for command injection via improperly sanitized Git URLs specified in Custom Behaviors. This issue affects versions 1.15.0 through 1.22.7, enabling users with crawler or administrator permissions to execute arbitrary operating system commands. Exploitation can lead to unauthorized access to application database records, archived items, browser profiles, and sensitive storage data. The vulnerability is addressed in version 1.22.8, prompting users to upgrade to maintain security.

Affected Version(s)

browsertrix >= 1.15.0, < 1.22.8

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.