Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-4786

Опубликовано: 13 апр. 2026
Источник: debian
EPSS Низкий

Описание

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14fixed3.14.5-1package
python3.13fixed3.13.14-1package
python3.13not-affectedtrixiepackage
python3.11not-affectedpackage
python3.9not-affectedpackage
python2.7not-affectedpackage
jythonnot-affectedpackage
pypy3fixed7.3.22+dfsg-1package
pypy3not-affectedtrixiepackage
pypy3not-affectedbookwormpackage
pypy3not-affectedbullseyepackage

Примечания

  • Incomplete fix for CVE-2026-4519, followup fixes listed there:

  • https://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/

  • https://github.com/python/cpython/issues/148169

  • https://github.com/python/cpython/pull/148170

  • https://github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53 (v3.14.5rc1)

EPSS

Процентиль: 21%
0.0029
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS3: 7.1
redhat
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS3: 7.1
nvd
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

msrc
3 месяца назад

Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

CVSS3: 7.1
github
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

EPSS

Процентиль: 21%
0.0029
Низкий