LIVE · cybersecurity feed
Live wire
cve recordlow

CVE-2026-4519

python · python

Published
CVSS3.3
Severitylow
WeaknessCWE-20
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

References

← Back to the CVE Tracker

Our coverage of CVE-2026-4519

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-4519.