AE Agent Errors
AE-6S0G2VMH

Browser agent's allowed_domains check is bypassed by placing an allowed domain in the URL's credentials part

SECURITY FAILUREseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: HIGH

Browser Use restricts agent navigation with an allowed_domains list checked in _is_url_allowed(), which took the URL netloc and split it at the first colon. A URL whose username portion is an allowed domain passed the check while the real host was different, letting the agent browse to arbitrary hosts including localhost and internal services.

Framework / agent
Browser Use · LLM browser automation agent
Remediation attempts
TESTED
Recurrence
not documented
Source languages
en
Updated
2026-09-30

Sources

Symptoms

  • URLs with an allowed domain in the basic-auth username portion pass the allowlist although the real host is different
  • The agent can be directed to localhost services and internal networks despite the domain whitelist
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents: GET /api/v1/cases/AE-6S0G2VMH. Pricing

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.