handleNavigate of the file pkg/browser/tool.go. Such manipulation of the argument args.targetUrl leads to information disclosure.
This vulnerability is listed as CVE-2026-15627. The attack may be performed from remote. In addition, an exploit is available.
Intelligence View
SOCIAL SHARE CARD GENERATOR