Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-54501: Browsertrix lets privileged users run OS commands

CVE-2026-54501 · published 11 days ago
Summary

Versions 1.15.0 through 1.22.7 of Browsertrix do not properly clean Git URLs used in custom behavior settings, so someone with crawler or admin rights can make the system execute any command they choose. This could let an attacker view, change, or delete stored archives, database records, and other service data. Upgrade to version 1.22.8 or later to stop the issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
webrecorder browsertrix >= 1.15.0, < 1.22.8
Original advisory text
Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviors
Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through /api/orgs/*/crawlconfigs/validate/custom-behavior. A user with crawler or administrator permission on the specific instance can supply a crafted Git URL that executes arbitrary operating-system commands in the backend pod. Open registration or hosted free-trial access can make the required role broadly obtainable. Successful exploitation can expose, modify, or delete application database records, archived items, browser profiles, storage data, proxy credentials, and other configured service data. This issue is fixed in version 1.22.8.
Severity
9.4 Critical
Exploitation
EPSS 1%
Type
CWE-20Improper Input Validation
CWE-77Command Injection
CWE-78OS Command Injection
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CWE-250Execution with Unnecessary Privileges
Timeline
Published17 Sep 2026
Updated26 Sep 2026
First seen17 Sep 2026
Sources
CVE-2026-54501 · MITRE
Track software like this
Free during beta