Impact
The Browser Agent Message Construction component of ntegrals openbrowser contains a flaw that allows an attacker to manipulate inputs in agent.ts, triggering excessive resource consumption. This weakness exemplifies uncontrolled resource consumption (CWE‑400) and may also lead to denial of service due to missing bounds checks (CWE‑404). The result can be an exhaustion of memory or CPU, potentially denying legitimate use of the service.
Affected Systems
The affected product is ntegrals openbrowser. Because the project uses a rolling release model, all commits up to the last published commit (067fc45d649baa961750da8e2f4a75d87c5c75c8) are potentially vulnerable, and no specific version numbers are available. The vendor has not released a patch or confirmed a fix.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be carried out remotely by sending crafted messages to the Browser Agent endpoint, and the public exploit demonstrates that the issue can be abused to consume resources. Environments that expose the endpoint to untrusted networks are at higher risk, and the lack of a published fix means the optimal defense is to limit exposure until an official update becomes available.
OpenCVE Enrichment