Browserbase Autobrowse Trace Artifact Handler Default Permissions Flaw
CVE-2026-12823 Published on June 21, 2026
Browserbase Autobrowse Trace Artifact default permission
A security flaw has been discovered in Browserbase up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default permissions. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Timeline
Advisory disclosed
VulDB entry created
VulDB entry last update
Weakness Types
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Products Associated with CVE-2026-12823
Want to know whenever a new CVE is published for Browserbase? stack.watch will email you.