CVE-2018-10895

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
12/07/2018
Last modified:
09/10/2019

Description

qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, resulting in arbitrary code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qutebrowser:qutebrowser:*:*:*:*:*:*:*:* 1.4.1 (excluding)