I submitted a remote code execution to the browser-use about 40 days ago. GHSA-r2x7-6hq9-qp7v
I am a bit stunned by the lack of response. Any safety concerns in this project?
I think most of the "outrage" is with the complete lack of validation and the "This is a known workflow within our platform" response more than the ban. Any plans to address the issue other than reactive bans?