{"id":"CVE-2026-94111","summary":"Tencent BrowserSkill through 0.3.0 Origin Validation Error in Local WebSocket Daemon","details":"Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM, and screenshots returned to the AI agent.","modified":"2026-09-24T03:30:36.941577493Z","published":"2026-09-20T11:56:07.027Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-346"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94111.json"},"references":[{"type":"WEB","url":"https://registry.npmjs.org"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94111.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94111"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/tencent-browserskill-through-0.3.0-origin-validation-error-in-local-websocket-daemon"},{"type":"REPORT","url":"https://github.com/Tencent/BrowserSkill/issues/273"},{"type":"PACKAGE","url":"https://github.com/Tencent/BrowserSkill"},{"type":"ARTICLE","url":"https://github.com/Tencent/BrowserSkill/blob/cli-v0.3.0/crates/bsk-cli/src/daemon/ws.rs#L36-L57"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tencent/browserskill","events":[{"introduced":"0"},{"fixed":"75e2c64abaf4b7cc75682d94b0c1fd5db0cbd5e5"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.3.0"},{"fixed":"0.3.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["ext-v0.2.1","dsh-plugin-v0.2.1","cli-v0.2.1","ext-v0.2.0","dsh-plugin-v0.2.0","cli-v0.2.0","dsh-plugin-v0.1.2","ext-v0.1.7","cli-v0.1.11","dsh-plugin-v0.1.1","ext-v0.1.6","cli-v0.1.10","ext-v0.1.5","cli-v0.1.9","ext-v0.1.4","cli-v0.1.8","ext-v0.1.3","cli-v0.1.7","cli-v0.1.6","ext-v0.1.2","cli-v0.1.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94111.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"}]}