---
id: CVE-2026-82640
title: >-
  browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys
  to disk in cleartext without encryption or access restrictions
summary: >-
  browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys
  to disk in cleartext without encryption or access restrictions. Attackers with
  read access to the temporary settings directory can recover provider API keys
  fr…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-312
published: '2026-08-30'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82640'
references:
  - url: 'https://github.com/browser-use/web-ui'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/browser-use/web-ui/blob/v3.0.0/src/webui/webui_manager.py
    label: disclosure@vulncheck.com
  - url: 'https://github.com/browser-use/web-ui/issues/736'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/browser-use-web-ui-2.0.0-through-3.0.0-cleartext-api-key-storage
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00072
epssPercentile: 0.0005
ingestedAt: '2026-08-30T23:59:28.129Z'
vendor: browser-use
product: web-ui
affected:
  - web-ui >= 2.0.0 <= 3.0.0
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-31T16:23:18.751860Z'
---

## Overview

browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
