๐Ÿ” CVE Alert

CVE-2026-54501

UNKNOWN 0.0

Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviors

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through /api/orgs/*/crawlconfigs/validate/custom-behavior. A user with crawler or administrator permission on the specific instance can supply a crafted Git URL that executes arbitrary operating-system commands in the backend pod. Open registration or hosted free-trial access can make the required role broadly obtainable. Successful exploitation can expose, modify, or delete application database records, archived items, browser profiles, storage data, proxy credentials, and other configured service data. This issue is fixed in version 1.22.8.

CWE CWE-20 CWE-77 CWE-78 CWE-88 CWE-250
Vendor webrecorder
Product browsertrix
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for webrecorder browsertrix

Be the first to know when new unknown vulnerabilities affecting webrecorder browsertrix are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

webrecorder / browsertrix
>= 1.15.0, < 1.22.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/webrecorder/browsertrix/security/advisories/GHSA-47vv-v544-r985 github.com: https://github.com/webrecorder/browsertrix/commit/a306afc3893a74ed0ec2407bdf0515ed52da8e46 github.com: https://github.com/webrecorder/browsertrix/releases/tag/v1.22.8