Pega Robotic Automation and Pega Browser Extension Arbitrary File-Write Vulnerability

Vulnerability

An arbitrary file-write vulnerability has been identified in Pega Robotic Automation versions 22.1 and R25, specifically for users running automations in Google Chrome or Microsoft Edge. This vulnerability allows a bad actor to create a malicious website that, when visited by a Robot Runtime user, could execute harmful code targeting the Pega Browser Extension.

Impact

Exploitation of this vulnerability could lead to unauthorized file writing, potentially allowing for the execution of malicious code or manipulation of files within the user's environment.

Remediation

Users are advised to update to Pega Browser Extension version 3.1.45 or later. For those using Pega Robotic Automation version 22.1, only the Pega Browser Extension update is necessary. Users on version R25 should update both Robot Studio and Robot Runtime to version 25.1.13.

Added: Apr 7, 2026, 5:03 PM
Updated: Apr 7, 2026, 5:03 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.0
remediation
0.0
relevance
5.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.