HIGH
browserless 1.44.0 through 2.56.7 File Protocol Restriction Bypass
Published Sep 16, 2026
7.1
HIGHCVSS 4.0
EPSS 0.45%
Description
browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary files. Attackers can navigate Playwright-driven browsers to file scheme URLs and access files accessible to the container process despite the ALLOW_FILE_PROTOCOL setting defaulting to false.
Affected products
-
- Version 1.44.0StatusaffectedConstraints<=2.56.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Browserless | Browserless | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-81069 Advisory
- https://github.com/browserless/browserless product
- https://github.com/browserless/browserless/blob/v2.50.1/src/browsers/browsers.cdp.ts#L105-L135 technical-description
- https://github.com/browserless/browserless/blob/v2.50.1/src/browsers/browsers.playwright.ts technical-description
- https://github.com/geo-chen/oss/blob/main/browserless.md technical-descriptionexploit
- https://www.vulncheck.com/advisories/browserless-1.44.0-through-2.56.7-file-protocol-restriction-bypass third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-81069 | Advisory | |
| https://github.com/browserless/browserless | product | |
| https://github.com/browserless/browserless/blob/v2.50.1/src/browsers/browsers.cdp.ts#L105-L135 | technical-description | |
| https://github.com/browserless/browserless/blob/v2.50.1/src/browsers/browsers.playwright.ts | technical-description | |
| https://github.com/geo-chen/oss/blob/main/browserless.md | technical-descriptionexploit | |
| https://www.vulncheck.com/advisories/browserless-1.44.0-through-2.56.7-file-protocol-restriction-bypass | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 16, 2026
Updated Sep 21, 2026
Reserved Sep 16, 2026
Link CVE-2026-92811
CISA Vulnrichment
Updated Sep 21, 2026
ENISA EUVD
EUVD-2026-81069 Assigner VulnCheck
Published Sep 16, 2026
Updated Sep 21, 2026
Exploited since n/a
Link EUVD-2026-81069