CVE-2026-54501

Source
https://cve.org/CVERecord?id=CVE-2026-54501
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54501.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54501
Aliases
  • GHSA-47vv-v544-r985
Published
2026-09-17T20:15:14Z
Modified
2026-09-19T03:47:08Z
Severity
  • 9.4 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviors
Details

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through /api/orgs/*/crawlconfigs/validate/custom-behavior. A user with crawler or administrator permission on the specific instance can supply a crafted Git URL that executes arbitrary operating-system commands in the backend pod. Open registration or hosted free-trial access can make the required role broadly obtainable. Successful exploitation can expose, modify, or delete application database records, archived items, browser profiles, storage data, proxy credentials, and other configured service data. This issue is fixed in version 1.22.8.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-20",
        "CWE-250",
        "CWE-77",
        "CWE-78",
        "CWE-88"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54501.json"
}
References

Affected packages

Git / github.com/webrecorder/browsertrix

Affected ranges

Type
GIT
Repo
https://github.com/webrecorder/browsertrix
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.15.0"
        },
        {
            "fixed": "1.22.8"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.15.0
v1.16.0
v1.16.1
v1.16.2
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.19.0
v1.19.0-beta.0
v1.19.1
v1.19.2
v1.19.3
v1.19.5
v1.19.6
v1.20.0
v1.20.1
v1.21.0
v1.21.0-beta.0
v1.21.1
v1.21.2
v1.21.3
v1.21.4
v1.21.5
v1.22.0
v1.22.0-beta.1
v1.22.1
v1.22.2
v1.22.3
v1.22.6
v1.22.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54501.json"