AE-6S0G2VMH
Browser agent's allowed_domains check is bypassed by placing an allowed domain in the URL's credentials part
SECURITY FAILUREseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: HIGH
Browser Use restricts agent navigation with an allowed_domains list checked in _is_url_allowed(), which took the URL netloc and split it at the first colon. A URL whose username portion is an allowed domain passed the check while the real host was different, letting the agent browse to arbitrary hosts including localhost and internal services.
- Framework / agent
- Browser Use · LLM browser automation agent
- Remediation attempts
- TESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- SECURITY ADVISORY Browser Use allows bypassing `allowed_domains` by putting a decoy domain in http auth username portion of a URL — https://github.com/browser-use/browser-use, retrieved 2026-09-29
- GITHUB PULL REQUEST fix security issue with url parsing — github.com/browser-use/browser-use, retrieved 2026-09-29
Symptoms
- URLs with an allowed domain in the basic-auth username portion pass the allowlist although the real host is different
- The agent can be directed to localhost services and internal networks despite the domain whitelist
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-6S0G2VMH. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.