CVE-2018-1000559 describes a Cross-Site Scripting (XSS) vulnerability in qutebrowser versions introduced from v0.11.0. This flaw allows an attacker to steal a user's browsing history by injecting JavaScript code through a specially crafted webpage title, which is then rendered on the qute://history page. Rated as Medium severity (CVSS 6.1), the attack requires user interaction to open the malicious page and then the history command. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. The issue has been addressed in qutebrowser versions v1.3.3 and v1.4.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.11.0, < 1.3.3CPE matchmatch criteria | cpe:2.3:a:qutebrowser:qutebrowser:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.