216.73.216.233

CVE-2026-4519

· Published 20/03/2026 15:16 · Modified 20/03/2026 21:17

Labels: CVE-2026-4519 2026-03-20CVE-2026-4519[email protected]

Essential information

Published
20/03/2026 15:16
Modified
20/03/2026 21:17
Author
Creator
CVSS
7.0 HIGH (v3) 7.0 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
python / python cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

References