Junglewise Threat Intelligence

CVE-2026-84833: Integral ntegrals OpenBrowser resource exhaustion in message construction

CVE-2026-84833 · Severity: medium · CVSS 4.3 · Published 2026-09-02

Executive brief

OpenBrowser is a browser automation tool that constructs and processes messages for controlling browser agents. A flaw in its message construction logic allows remote attackers to trigger excessive resource consumption, potentially causing performance degradation or denial of service without requiring authentication.

Technical details

The vulnerability exists in the Browser Agent Message Construction functionality within packages/core/src/agent/agent.ts of ntegrals OpenBrowser. An unauthenticated remote attacker can exploit a resource consumption flaw by sending specially crafted messages that cause the agent to allocate excessive system resources. The vulnerability is accessible over the network without authentication. While a public exploit exists and the issue has been disclosed, the vendor has not responded or released a patch. The product uses a rolling release model, making specific affected versions difficult to identify.

Affected products

  • Integral OpenBrowser up to commit 067fc45d649baa961750da8e2f4a75d87c5c75c8

Timeline

  • 2026-09-02: disclosed
  • other: Public exploit available

References