Impact
Browsertrix allows an attacker who can provide a custom Git URL to inject arbitrary operating‑system commands via the /api/orgs/*/crawlconfigs/validate/custom-behavior endpoint. The vulnerability stems from improper command sanitization. Successful exploitation can read, modify, or delete the application database, archived content, browser profiles, storage data, proxy credentials, and other configured service data. This flaw gives the attacker full control of the backend pod, resulting in complete compromise of the affected instance.
Affected Systems
Vulnerable releases are Browsertrix versions 1.15.0 up to but not including 1.22.8, which can be run as a self‑hosted instance or accessed through Webrecorder’s hosted service. All users with crawler or administrator roles on these instances, and users who can register a free trial on the hosted service, are able to supply the malicious Git URL. The fix is delivered in release 1.22.8.
Risk and Exploitability
The CVSS score of 9.4 reflects the severity and complete loss of confidentiality, integrity, and availability. An EPSS score of 1% indicates that the probability of exploitation is low but not negligible. The vulnerability is not listed in the CISA KEV catalog, so there is no published exploit yet. The attack vector is remote, via the exposed HTTP API, and requires attacker possession of crawler or administrator privileges or the ability to register a free trial. If exploited, the attacker can execute any operating‑system command within the container, fully compromising the instance.
OpenCVE Enrichment