CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-55536

criticalCVSS 9.1covered by 2 sourcesfirst seen 2026-08-25
Summary praisonai/browser/server.py validates incoming WebSocket connections using a Chrome extension Origin check. The regex chrome-extension://[a-z0-9]{32} is applied with re.match(), which only anchors at the start of the string, not the end. Any Origin header with more than 32 alphanumeric characters after chrome-extension:// — including non-alphanumeric trailing characters — passes the check. This is a patch bypass of GHSA-8x8f-54wf-vv92. That advisory triggered the addition of origin validation; this finding shows the validation is bypassable by any WebSocket client that forges an Origin header. After bypassing, the attacker can send start_session commands that are executed by any Chrome extension currently connected to the server — causing the extension to perform arbitrary browser automation including cookie theft and screenshot capture. Details Vulnerable code — browser/server.py line 186: elif parsed_origin.scheme == "chrome-extension" and \ re.match(r"chrome-extension://[a-z0-9]{32}", origin): is_allowed = True re.match() returns a match object if the pattern matches at the beginning of the string; trailing characters after the 32nd are not evaluated. re.fullmatch() (or anchoring with $) is required to enforce exact length. There is no other authentication mechanism in _handle_connection(). Confirmed by source inspection: - No bearer token check - No API key check - No extension ID allowlist - Origin header regex is the only gate before websocket.accept() **After connection, start_session reaches _handle_start_session() (lines 283-414)**, which: 1. Creates a BrowserAgent with the attacker-specified goal and model 2. Broadcasts start_automation to every connected Chrome extension 3. The extension then performs the goal on the user's browser PoC Requirements: PraisonAI browser server running on default 127.0.0.1:8765 Start the server: python -m praisonai browser --port 8765 or: from praisonai.browser.server import BrowserServer; BrowserServer().

⚡ Watch CVE-2026-55536

Get an email if CVE-2026-55536 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-55536

CVE.org record

Embed the live status

CVE-2026-55536 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-55536 status](https://www.csirts.com/badge/CVE-2026-55536)](https://www.csirts.com/cve/CVE-2026-55536)