CVE-2026-4519

HIGH EPSS 12.0%
Published Mar 20, 20263mo ago · Modified Jun 17, 20261w ago
7.0 CVSS 4.0
High
Find Similar
Published Mar 20, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago

Description

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

CVSS Details

Base Score
7.0
Exploitability
Impact
Vector string
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction A
Scope X

Threat Intelligence

EPSS Exploit Probability
12.0% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-20 Improper Input Validation Validation

Affected Products 9

VendorProductVersionRange
pythonpython* <3.13.13
pythonpython*≥3.14.0  –  <3.14.4
pythonpython3.15.0any
pythonpython3.15.0any
pythonpython3.15.0any
pythonpython3.15.0any
pythonpython3.15.0any
pythonpython3.15.0any
pythonpython3.15.0any

References 16

  • openwall.com http://www.openwall.com/lists/oss-security/2026/03/20/1
    Mailing ListThird Party Advisory
  • github.com https://github.com/python/cpython/commit/3681d47a440865aead912a054d4599087b4270dd
    Patch
  • github.com https://github.com/python/cpython/commit/43fe06b96f6a6cf5cfd5bdab20b8649374956866
    Patch
  • github.com https://github.com/python/cpython/commit/591ed890270c5697b013bf637029fb3e6cd2d73e
    Patch
  • github.com https://github.com/python/cpython/commit/594b5a05dc9913880ac92eded440defbf32a28d1
    Patch
  • github.com https://github.com/python/cpython/commit/82a24a4442312bdcfc4c799885e8b3e00990f02b
    Patch
  • github.com https://github.com/python/cpython/commit/89bfb8e5ed3c7caa241028f1a4eac5f6275a46a4
    Patch
  • github.com https://github.com/python/cpython/commit/9669a912a0e329c094e992204d6bdb8787024d76
    Patch
  • github.com https://github.com/python/cpython/commit/96fc5048605863c7b6fd6289643feb0e97edd96c
    Patch
  • github.com https://github.com/python/cpython/commit/ad4d5ba32af4d80b0dfa2ba9d8203bfb219e60a5
    Patch
  • github.com https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48
    Patch
  • github.com https://github.com/python/cpython/commit/cc023511238ad93ecc8796157c6f9139a2bb2932
    Patch
  • github.com https://github.com/python/cpython/commit/ceac1efc66516ac387eef2c9a0ce671895b44f03
    Patch
  • github.com https://github.com/python/cpython/issues/143930
    Issue TrackingPatch
  • github.com https://github.com/python/cpython/pull/143931
    Issue TrackingPatch
  • mail.python.org https://mail.python.org/archives/list/security-announce@python.org/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS/
    Vendor Advisory

Remediation

  • github.com https://github.com/python/cpython/commit/3681d47a440865aead912a054d4599087b4270dd
    Patch
  • github.com https://github.com/python/cpython/commit/43fe06b96f6a6cf5cfd5bdab20b8649374956866
    Patch
  • github.com https://github.com/python/cpython/commit/591ed890270c5697b013bf637029fb3e6cd2d73e
    Patch
  • github.com https://github.com/python/cpython/commit/594b5a05dc9913880ac92eded440defbf32a28d1
    Patch
  • github.com https://github.com/python/cpython/commit/82a24a4442312bdcfc4c799885e8b3e00990f02b
    Patch
  • github.com https://github.com/python/cpython/commit/89bfb8e5ed3c7caa241028f1a4eac5f6275a46a4
    Patch
  • github.com https://github.com/python/cpython/commit/9669a912a0e329c094e992204d6bdb8787024d76
    Patch
  • github.com https://github.com/python/cpython/commit/96fc5048605863c7b6fd6289643feb0e97edd96c
    Patch
  • github.com https://github.com/python/cpython/commit/ad4d5ba32af4d80b0dfa2ba9d8203bfb219e60a5
    Patch
  • github.com https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48
    Patch
  • github.com https://github.com/python/cpython/commit/cc023511238ad93ecc8796157c6f9139a2bb2932
    Patch
  • github.com https://github.com/python/cpython/commit/ceac1efc66516ac387eef2c9a0ce671895b44f03
    Patch
  • github.com https://github.com/python/cpython/issues/143930
    Issue TrackingPatch
  • github.com https://github.com/python/cpython/pull/143931
    Issue TrackingPatch