GHSA-cccx-m78h-m3xwHighCVSS 7.1

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be...

Published
April 14, 2026
Last Modified
August 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

🔗 References (60)