Description
Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through /api/orgs/*/crawlconfigs/validate/custom-behavior. A user with crawler or administrator permission on the specific instance can supply a crafted Git URL that executes arbitrary operating-system commands in the backend pod. Open registration or hosted free-trial access can make the required role broadly obtainable. Successful exploitation can expose, modify, or delete application database records, archived items, browser profiles, storage data, proxy credentials, and other configured service data. This issue is fixed in version 1.22.8.
Published: 2026-09-17
Score: 9.4 Critical
EPSS: 1.2% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

Browsertrix allows an attacker who can provide a custom Git URL to inject arbitrary operating‑system commands via the /api/orgs/*/crawlconfigs/validate/custom-behavior endpoint. The vulnerability stems from improper command sanitization. Successful exploitation can read, modify, or delete the application database, archived content, browser profiles, storage data, proxy credentials, and other configured service data. This flaw gives the attacker full control of the backend pod, resulting in complete compromise of the affected instance.

Affected Systems

Vulnerable releases are Browsertrix versions 1.15.0 up to but not including 1.22.8, which can be run as a self‑hosted instance or accessed through Webrecorder’s hosted service. All users with crawler or administrator roles on these instances, and users who can register a free trial on the hosted service, are able to supply the malicious Git URL. The fix is delivered in release 1.22.8.

Risk and Exploitability

The CVSS score of 9.4 reflects the severity and complete loss of confidentiality, integrity, and availability. An EPSS score of 1% indicates that the probability of exploitation is low but not negligible. The vulnerability is not listed in the CISA KEV catalog, so there is no published exploit yet. The attack vector is remote, via the exposed HTTP API, and requires attacker possession of crawler or administrator privileges or the ability to register a free trial. If exploited, the attacker can execute any operating‑system command within the container, fully compromising the instance.

Generated by OpenCVE AI on September 19, 2026 at 19:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Browsertrix 1.22.8 or later.
  • Disable or limit access to the /api/orgs/*/crawlconfigs/validate/custom-behavior endpoint, ensuring only trusted administrators can use it while the fix is pending.
  • If an upgrade is not immediately possible, remove or lock custom behavior functionality until the vulnerability is patched.
  • Review user permissions and restrict crawler roles to trusted users to reduce the attack surface.

Generated by OpenCVE AI on September 19, 2026 at 19:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Webrecorder
Webrecorder browsertrix
Vendors & Products Webrecorder
Webrecorder browsertrix

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through /api/orgs/*/crawlconfigs/validate/custom-behavior. A user with crawler or administrator permission on the specific instance can supply a crafted Git URL that executes arbitrary operating-system commands in the backend pod. Open registration or hosted free-trial access can make the required role broadly obtainable. Successful exploitation can expose, modify, or delete application database records, archived items, browser profiles, storage data, proxy credentials, and other configured service data. This issue is fixed in version 1.22.8.
Title Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviors
Weaknesses CWE-20
CWE-250
CWE-77
CWE-78
CWE-88
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Webrecorder Browsertrix
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T20:23:40.136Z

Reserved: 2026-06-15T18:01:15.511Z

Link: CVE-2026-54501

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:15.707

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:00:14Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-250

    Execution with Unnecessary Privileges

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')