Impact
browserless versions 1.44.0 through 2.56.7 do not enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read files from the underlying container. The vulnerability is a form of information exposure (CWE‑200) that can lead to the disclosure of sensitive data stored in the container file system. Attackers are able to issue Playwright commands that navigate to file:// scheme URLs and retrieve any file accessible to the container process.
Affected Systems
The affected product is the browserless server, open source edition, as distributed under the browserless:browserless CPE. All releases in the range 1.44.0 to 2.56.7 are impacted, regardless of the underlying operating system or container runtime.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high risk, yet the EPSS score of less than 1% suggests that exploitation is currently unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog, reflecting its newer status. Exploitation requires possession of a valid authentication token to access the Playwright websocket endpoints. An attacker with such a token can direct the browserless service to open arbitrary local files, exposing confidential information. The attack vector is internal to the browserless instance; attackers must either compromise the token or exploit a misconfigured environment where tokens are publicly exposed.
OpenCVE Enrichment