External risk intelligence

Browsertrix Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-54501

The vulnerability exists in a web-based crawling service and an API endpoint used for configuration. These components are commonly exposed as internet-facing web applications or services. While authentication is required, the service's role as a web-archiving tool and the mention of open registration or hosted trials make public internet exposure of the vulnerable surface common.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Browsertrix, a web archiving service. The flaw allows unauthorized command execution through a specific API endpoint when handling Git URLs in custom configurations. This could potentially expose, modify, or delete sensitive application data.

  • A security flaw allows unauthorized command execution.
  • It affects web archiving services and data.
  • Confirm relevance and exposure of the service.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted Git URL to an API endpoint in the Browsertrix crawling service. This endpoint is designed to validate custom behaviors for crawls. If an attacker can get a user with crawler or administrator permissions to trigger this validation, the malicious Git URL can be used to execute arbitrary commands on the server. This is particularly concerning because open registration or free trial access could make it easier for attackers to obtain the necessary permissions.

  • Requires crawler or administrator permission.
  • Triggered by validating a custom behavior.
  • Risk of arbitrary code execution and data compromise.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an authenticated user with crawler or administrator permissions could leverage a flaw in how the service handles Git URLs within custom behaviors to execute arbitrary operating system commands on the backend. This could affect application data, archived items, and configured service information.

  • Application database records.
  • Commands injected via crafted Git URLs.
  • Data exposure, modification, or deletion.

Operational Fix

Recommended remediation, mitigation, and detection steps

The application owner is responsible for addressing this critical vulnerability in Browsertrix. The first practical step is to identify all instances of the affected service, confirm their exposure and business criticality, and then engage the appropriate team for remediation.

  • Application owners should manage this issue.
  • Verify all instance exposures and criticality.
  • Plan and coordinate remediation efforts.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Browsertrix?

Browsertrix is a high-fidelity web archiving platform that automates the collection of websites by simulating browser behavior. Organizations use it to capture and preserve web content for research or historical record-keeping. The service can be operated as a self-hosted instance or through Webrecorder's hosted solution, relying on backend pods to manage the complex crawling processes that transform live web pages into archival formats.

How does CVE-2026-54501 allow command injection?

This vulnerability is classified as improper input validation, specifically involving OS Command Injection (CWE-78). The application fails to properly sanitize Git URLs submitted through its configuration API. Because these URLs are processed directly by the backend, a crafted input allows an attacker to break out of the intended operation and force the underlying server to execute arbitrary system commands with the privileges of the crawling service.

What triggers the command injection in Browsertrix?

The flaw is triggered when a user with crawler or administrator privileges submits a malicious Git URL to the custom-behavior validation endpoint. It is important to note that this is not an unauthenticated attack; the process requires active credentials for the instance. Simply navigating the site or using standard archiving features without accessing the specific validation API for custom behaviors does not trigger the vulnerability.

Is my Browsertrix instance at risk?

According to Halo Surface Signal, this vulnerability is a high priority because Browsertrix is typically deployed as an internet-facing web application. If your instance allows open registration or provides hosted trial access, the risk increases significantly, as unauthorized parties may easily obtain the crawler or administrator permissions necessary to execute the malicious commands.

How do I address CVE-2026-54501?

The primary response is to upgrade your deployment to version 1.22.8 or later, where this validation flaw has been corrected. Before applying the update, verify all instances of the service within your environment to understand which are internet-facing. Coordinate with your engineering teams to prioritize patching these systems, especially those that permit public account creation or have wide user access.

References