Description
A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default permissions. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The first version of the CVE listed Browserbase itself as affected product. This was incorrect as this issue does affect browserbase/skills instead. The vendor was contacted early about this disclosure.
Published: 2026-06-21
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A security flaw in Browserbase Skills up to 20260526 causes the Autobrowse Trace Artifact Handler to create trace files with improperly set permissions, allowing any local user to read, modify, or delete them. The resulting vulnerability could lead to leakage of sensitive information or tampering with diagnostic logs. An unknown function within the Autobrowse Trace Artifact Handler is impacted, and public proof‑of‑concept exploits demonstrate that the insecure default permissions can be leveraged locally. This weakness is classified as Improper Privilege Management (CWE‑266) and Incorrect Permissions (CWE‑276).

Affected Systems

All builds of Browserbase Skills released through 20260526 are affected. The vulnerability is confined to the Autobrowse Trace Artifact Handler component and does not impact other parts of the product. No other vendors or products are enumerated.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in CISA KEV. The attack requires local access; after obtaining local privileges, the attacker can exploit the insecure permissions to read or modify trace artifacts. The public proof‑of‑concept exploits confirm the flaw is exploitable.

Generated by OpenCVE AI on August 2, 2026 at 01:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Browserbase Skills to a version newer than 20260526 when a vendor patch becomes available
  • If no patch is available, enforce correct file permissions on the trace artifact directory (e.g., chmod 600 or equivalent) to deny write and read access to non‑privileged users
  • Implement monitoring or audit logging for the trace artifact directory to detect unauthorized modifications

Generated by OpenCVE AI on August 2, 2026 at 01:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 03 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Browserbase up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default permissions. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default permissions. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The first version of the CVE listed Browserbase itself as affected product. This was incorrect as this issue does affect browserbase/skills instead. The vendor was contacted early about this disclosure.
Title Browserbase Autobrowse Trace Artifact default permission Browserbase Skills Autobrowse Trace Artifact default permission
First Time appeared Browserbase skills
CPEs cpe:2.3:a:browserbase:browserbase:*:*:*:*:*:*:*:* cpe:2.3:a:browserbase:skills:*:*:*:*:*:*:*:*
Vendors & Products Browserbase skills

Tue, 23 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Jun 2026 00:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Browserbase up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default permissions. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Browserbase Autobrowse Trace Artifact default permission
First Time appeared Browserbase
Browserbase browserbase
Weaknesses CWE-266
CWE-276
CPEs cpe:2.3:a:browserbase:browserbase:*:*:*:*:*:*:*:*
Vendors & Products Browserbase
Browserbase browserbase
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Browserbase Browserbase Skills
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-03T04:05:07.713Z

Reserved: 2026-06-21T13:17:40.650Z

Link: CVE-2026-12823

cve-icon Vulnrichment

Updated: 2026-06-23T14:02:41.157Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T01:45:06Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-276

    Incorrect Default Permissions