PyPI: browser-use

CVE-2025-47241

Safety vulnerability ID: SFTY-20250503-41630

Safety legacy ID: pyup.io-77047

In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.

Created at: May 22, 2026Updated at: May 22, 2026

Overview

Browser Use allows bypassing `allowed_domains` by putting a decoy domain in http auth username portion of a URL

Advisory

In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.

Affected Package

Affecting browser-use package, versions
<0.1.45

Also affects

---

How to Fix

Upgrade
browser-use
to
0.1.45
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more