CVE-2026-92811EPSS p37.1%
CVE-2026-92811CVE-2026-92811
Description
browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary files. Attackers can navigate Playwright-driven browsers to file scheme URLs and access files accessible to the container process despite the ALLOW_FILE_PROTOCOL setting defaulting to false.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 0.45% probability of exploitation · percentile 37.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-22 |