Impact
A security flaw in Browserbase Skills up to 20260526 causes the Autobrowse Trace Artifact Handler to create trace files with improperly set permissions, allowing any local user to read, modify, or delete them. The resulting vulnerability could lead to leakage of sensitive information or tampering with diagnostic logs. An unknown function within the Autobrowse Trace Artifact Handler is impacted, and public proof‑of‑concept exploits demonstrate that the insecure default permissions can be leveraged locally. This weakness is classified as Improper Privilege Management (CWE‑266) and Incorrect Permissions (CWE‑276).
Affected Systems
All builds of Browserbase Skills released through 20260526 are affected. The vulnerability is confined to the Autobrowse Trace Artifact Handler component and does not impact other parts of the product. No other vendors or products are enumerated.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in CISA KEV. The attack requires local access; after obtaining local privileges, the attacker can exploit the insecure permissions to read or modify trace artifacts. The public proof‑of‑concept exploits confirm the flaw is exploitable.
OpenCVE Enrichment