MEDIUM SEVERITYCONFIRMED
_filter_sensitive_data_from_string leaks suffix when secrets share a prefix
Package
browser-use
Version
0.12.5
Verified
2026-03-28
Description
browser-use's `AgentHistory._filter_sensitive_data_from_string` iterates secrets in Python dict insertion order without sorting by length. When a shorter secret is a prefix of a longer one (e.g., `'sk-ant'` and `'sk-ant-abc123xyz'`), the shorter replacement fires first, leaving the unique suffix (`-abc123xyz`) as visible plaintext in agent history files and logs.
Reproduction
sensitive = {'api_prefix': 'sk-ant', 'full_api_key': 'sk-ant-abc123xyz'}
text = 'Authorization: Bearer sk-ant-abc123xyz'
# After filtering:
# 'Authorization: Bearer <secret>api_prefix</secret>-abc123xyz'
# '-abc123xyz' is plaintext — LEAK