CVE 6.9 MEDIUM

BrowserOperator browser-operator-core server.js startsWith path traversal_CVE-2026-7234

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/component_server/server.js. Executing a manipulation of the argument request.url can lead to path traversal. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Basic Information

ID CVE-2026-7234
Source VulDB
Published Apr 28, 2026 at 06:15

Affected Product

Vendor BrowserOperator
Product browser-operator-core
Version 0.1
Affected Versions BrowserOperator browser-operator-core 0.1
BrowserOperator browser-operator-core 0.2
BrowserOperator browser-operator-core 0.3
BrowserOperator browser-operator-core 0.4
BrowserOperator browser-operator-core 0.5
BrowserOperator browser-operator-core 0.6.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.