Fetching from the wire…
Public story · 2026-08-17 · high
Version 0.13.8 fixes an access-control bypass and a hidden-text leak, tucked inside a routine feature update.
Why now: browser-use runs against live, untrusted web pages by design, so anyone who hasn't updated past 0.13.7 has been exposed since before this release landed.
browser-use released version 0.13.8 on August 16, its first update in three weeks, and buried two security fixes inside a list of feature additions. Domain restrictions are supposed to stop an autonomous browser agent from acting outside an approved site list. The release patches a registry bug that let those restrictions get bypassed when a page had an empty URL, per the GitHub release notes.
The other fix addresses a DOMTreeSerializer bug that leaked paint-order-occluded text to the LLM steering the browser. That's text a person moderating the session never sees on screen, but the model reads it anyway. The release notes don't say how the bug was found or how long it existed.
Elsewhere, the release adds first-party OpenClaw skill support (#5476) and MCP readOnlyHint annotations on read-only tools (#5246). It also makes CallToolResult.isError surface as a failed ActionResult (#5235) instead of failing silently, and switches the default model to bu-2-0-mini-preview.
Each link below shares sources, entities, or timing with this story.
Codex CLI uses MCP / Shared entities / Same source domain / Earlier coverage / Tension
Linked by a graph relationship (Codex CLI uses MCP); both cover GitHub, LLM, MCP, OpenClaw; reported by the same outlet (github.com).
LLM uses OpenAI / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (LLM uses OpenAI); both cover August, GitHub, MCP; reported by the same outlet (github.com).
BlueRock criticizes MCP / Shared entities / Earlier coverage / Tension
Linked by a graph relationship (BlueRock criticizes MCP); both cover LLM, MCP, Those, URL; earlier LLM coverage from 2026-07-07.
LLM uses OpenAI / Shared entities / Same source domain / Shared topic
Linked by a graph relationship (LLM uses OpenAI); both cover August, GitHub, MCP; reported by the same outlet (github.com).
Cisco criticizes MCP / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (Cisco criticizes MCP); both cover August, GitHub, MCP; reported by the same outlet (github.com).
Claude Code uses MCP / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (Claude Code uses MCP); both cover August, GitHub, MCP; reported by the same outlet (github.com).
OpenCode supports MCP / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (OpenCode supports MCP); both cover GitHub, MCP, OpenClaw; reported by the same outlet (github.com).
LLM uses OpenAI / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (LLM uses OpenAI); both cover August, GitHub, MCP; overlapping topics (august, skill).