Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4786

Опубликовано: 13 апр. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

A flaw was found in the Python webbrowser.open() API. If a specially crafted URL containing "%action" is processed, an attacker could bypass a previous mitigation for CVE-2026-4519. This bypass allows for command injection into the underlying shell, potentially leading to arbitrary code execution.

Отчет

This flaw in the Python webbrowser.open() API allows for command injection and arbitrary code execution when processing specially crafted URLs containing "%action". This bypasses a previous mitigation for CVE-2026-4519.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7python3Affected
Red Hat Enterprise Linux 8python2Not affected
Red Hat Enterprise Linux 8python36Not affected
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat Enterprise Linux 8python38Will not fix
Red Hat Enterprise Linux 8python39Will not fix
Red Hat Enterprise Linux 10python3.12FixedRHSA-2026:1071127.04.2026
Red Hat Enterprise Linux 10python3.14FixedRHSA-2026:1901919.05.2026
Red Hat Enterprise Linux 10python3.12FixedRHSA-2026:1906419.05.2026
Red Hat Enterprise Linux 10python3.14FixedRHSA-2026:2858124.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2458049python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API

EPSS

Процентиль: 21%
0.0029
Низкий

7.1 High

CVSS3

Связанные уязвимости

ubuntu
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

nvd
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

msrc
3 месяца назад

Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

debian
4 месяца назад

Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ...

github
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

EPSS

Процентиль: 21%
0.0029
Низкий

7.1 High

CVSS3