logo

Getting RCE on browser-use/web-ui AI Agent Instances

ID: 29deb537-2b98-59ae-9cd7-4f37bd5369ce

STIX ID: report--29deb537-2b98-59ae-9cd7-4f37bd5369ce

Feed Name: Kudelski Security

Threat Score
70/100

Date Published: 2025-04-23

Date Updated: 2026-07-22

...
...

This report details a critical insecure-deserialization vulnerability in the browser-use/web-ui project: web-ui saves and loads settings with Python pickle, allowing an attacker-supplied .pkl file to execute arbitrary code server-side. The author demonstrates a PoC that exfiltrates environment variables and outlines an additional attack vector where disabled Chromium security flags let a malicious webpage upload a crafted pickle via an iframe, enabling compromise of both public and privately running instances; the report recommends switching to a safe serialization format (e.g., JSON) and notes the timeline of responsible disclosure and eventual patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.