Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <e053dfa9-848e-465e-bab0-a7553d512716@oracle.com>
Date: Mon, 13 Apr 2026 15:17:48 -0700
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com
Subject: [CVE-2026-4786] CPython: Incomplete mitigation of
 CVE-2026-4519, %action expansion for command injection to webbrowser.open()




-------- Forwarded Message --------
Subject: 	[Security-announce][CVE-2026-4786] Incomplete mitigation of 
CVE-2026-4519, %action expansion for command injection to webbrowser.open()
Date: 	Mon, 13 Apr 2026 21:53:53 +0000
From: 	Seth Larson <seth@...hon.org>
Reply-To: 	security-sig@...hon.org
To: 	security-announce@...hon.org



There is a HIGH severity vulnerability affecting CPython.

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the
mitigation could be bypassed for certain browser types the "webbrowser.open()"
API could have commands injected into the underlying shell. See CVE-2026-4519
for details.

Please see the linked CVE ID for the latest information on affected versions:

* https://www.cve.org/CVERecord?id=CVE-2026-4786
* https://github.com/python/cpython/pull/148170

_______________________________________________
Security-announce mailing list -- security-announce@...hon.org
To unsubscribe send an email to security-announce-leave@...hon.org
https://mail.python.org/mailman3//lists/security-announce.python.org

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.