Path Traversal Vulnerability in BrowserOperator's Browser-Operator-Core
CVE-2026-7234
Key Information:
- Vendor
Browseroperator
- Status
- Vendor
- CVE Published:
- 28 April 2026
Badges
What is CVE-2026-7234?
A path traversal vulnerability has been discovered in BrowserOperator's browser-operator-core up to version 0.6.0. The issue arises in the 'startsWith' function within the scripts/component_server/server.js file. Attackers can manipulate the 'request.url' parameter, potentially leading to unauthorized access to system files and directories. This flaw poses a significant risk as it can be exploited remotely, enabling malicious actors to gain sensitive information from the server. The project team was notified of the vulnerability through an issue report, but no response has been documented to date.
Affected Version(s)
browser-operator-core 0.1
browser-operator-core 0.2
browser-operator-core 0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
