← back
CVE-2025-47241mediumCWE-647

CVE-2025-47241

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4epss 0.5%
exploitation probability
0.5%top 63% of all CVEs
observed exploitation
nono source reports it
In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N