remote-browser
Audited by Socket on Sep 29, 2026
2 alerts found:
Anomalyx2The script has deployment-management functionality, but unvalidated registry directory names can reach JavaScript evaluation in list, and a tampered configured URL can receive the stored bearer token in status. The delete directory prefix check also permits path traversal if the config is attacker-controlled. These risks depend on control of local registry/configuration data; no clear standalone malware behavior is present.
No clear malware behavior is present. The authenticated browser-fetch and session endpoints permit navigation to arbitrary HTTP/HTTPS URLs without host or address restrictions, creating a meaningful SSRF risk if the browser can reach internal or sensitive network resources. Restrict destinations and account for redirects and DNS resolution.