CVE-2026-4519

Severity CVSS v4.0:
HIGH
Type:
CWE-20 Input Validation
Publication date:
20/03/2026
Last modified:
16/04/2026

Description

The webbrowser.open() API would accept leading dashes in the URL which <br /> could be handled as command line options for certain web browsers. New <br /> behavior rejects leading dashes. Users are recommended to sanitize URLs <br /> prior to passing to webbrowser.open().

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.13.13 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.14.0 (including) 3.14.4 (excluding)
cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:python:python:3.15.0:alpha7:*:*:*:*:*:*