Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 13 Apr 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | |
| Title | Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: PSF
Published:
Updated: 2026-04-13T21:56:25.643Z
Reserved: 2026-03-24T19:25:48.269Z
Link: CVE-2026-4786
No data.
Status : Received
Published: 2026-04-13T22:16:30.413
Modified: 2026-04-13T22:16:30.413
Link: CVE-2026-4786
No data.
OpenCVE Enrichment
No data.
Weaknesses