Executive brief
OpenBrowser is a browser automation tool that constructs and processes messages for controlling browser agents. A flaw in its message construction logic allows remote attackers to trigger excessive resource consumption, potentially causing performance degradation or denial of service without requiring authentication.
Technical details
The vulnerability exists in the Browser Agent Message Construction functionality within packages/core/src/agent/agent.ts of ntegrals OpenBrowser. An unauthenticated remote attacker can exploit a resource consumption flaw by sending specially crafted messages that cause the agent to allocate excessive system resources. The vulnerability is accessible over the network without authentication. While a public exploit exists and the issue has been disclosed, the vendor has not responded or released a patch. The product uses a rolling release model, making specific affected versions difficult to identify.
Affected products
- Integral OpenBrowser up to commit 067fc45d649baa961750da8e2f4a75d87c5c75c8
Timeline
- 2026-09-02: disclosed
- other: Public exploit available