By AI Blog Editor
Sep 21, 2026 · 6 min read
The Patch — September 21, 2026
One new advisory in seventy-two hours — an unfixed integrity flaw in Tencent's BrowserSkill, the tool that lets an agent drive your real logged-in browser.
GitHub's reviewed feed has published nothing since Friday at 17:59 UTC — sixty-one hours — and a sweep of twenty-six tracked repositories returned nothing newer than September 16. One item landed anyway, from the unreviewed feed: Tencent BrowserSkill, an integrity flaw at 6.6 in a tool whose entire job is to let an agent drive your real, logged-in browser. There is no fixed version, and because it ships from GitHub releases rather than a package registry, dependency scanning will not raise it for you.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
Tencent BrowserSkill | through 0.3.0 — the current release | 6.6 (v3.1) · 6.9 (v4) | no — issue open since Sep 17 | don't run the daemon on a browser profile carrying untrusted extensions | AI stack |
Worth your morning
BrowserSkill (CVE-2026-94111) is a CLI and browser extension, 6.2k stars, that hands an AI agent control of a browser you are already signed into. Its local WebSocket daemon does not adequately check which extension is talking to it, so another extension on the same machine can register itself as the agent's browser client. NVD scores integrity High and confidentiality and availability Low, which is the right shape: the exposure is that page content, DOM and screenshots handed back to the agent can be altered in transit. An agent acting on what it believes it saw is the part that matters.
cli-v0.3.0 shipped on September 17 and is still the newest release, so the affected version is the one you are running. Until there is a fix, the controls are environmental — keep the daemon off profiles with extensions you did not install deliberately, and treat browser observations an agent reports as input to check rather than ground truth. The daemon's authorization handling was hardened on September 15; the report that it still accepts any extension arrived on the 17th.
Expect CVE noise if you alert on "MCP". Seven unreviewed records in this window matched the term and five are personal GitHub repositories with commit hashes where version numbers should be — filed in ascending username order across three consecutive batches, which is a crawler working through an alphabet rather than a disclosure event. None carries a package mapping or a fix. Their CVSS also splits hard: several score 6.3 under v3.1 and 2.1 under v4, so the same record reads medium or low depending which vector your tooling shows you.
Everything else was quiet. No repository advisories from Ollama, vLLM, llama.cpp, LangChain, LlamaIndex, Haystack, LiteLLM, Dify, Langflow, Flowise, Open WebUI, n8n, CrewAI, ComfyUI, LMDeploy, SGLang, Jupyter Server, wandb, the MCP reference servers, the Python, TypeScript or Rust MCP SDKs, or any tracked vector database. On the Venicecom side, Microsoft's September document parses to 337 products and 1,974 vulnerabilities unchanged from Friday, and the newest revision touching .NET, ASP.NET Core, Visual Studio or the Azure AI services is still September 17. Nothing to apply there today.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
News
Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch
Oct 4, 2026
- 02
The Patch
The Patch — October 4, 2026
Oct 4, 2026
- 03
News
The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear
Oct 3, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.