CVE-2026-4519 describes a vulnerability in the `webbrowser.open()` API, part of Python's standard library, where it improperly accepts URLs containing leading dashes. This flaw allows certain web browsers to interpret these dashes as command-line options, potentially leading to high confidentiality and integrity impacts on a user's system. Rated High with a CVSSv4 score of 7.0, exploitation requires local access and user interaction, though the attack complexity is low. Currently, there is no evidence of active exploitation, nor are public exploit modules available, and community attention remains minimal. Users are advised to sanitize URLs before passing them to `webbrowser.open()` to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 3.13.13CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.14.0, < 3.14.4CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
< 3.13.13CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
3.15.0CPE matchmatch criteria | cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:* | ||
3.15.0CPE matchmatch criteria | cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.