CVE-2026-4786

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
CVSS

No CVSS.

Configurations

No configuration.

History

29 Apr 2026, 16:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53 -
  • () https://github.com/python/cpython/commit/d6d68494be70bdbda20f89f83801ba52ec37daa4 -

14 Apr 2026, 15:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca -
  • () https://github.com/python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fff -
  • () https://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769 -

13 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-13 22:16

Updated : 2026-04-29 16:16


NVD link : CVE-2026-4786

Mitre link : CVE-2026-4786

CVE.ORG link : CVE-2026-4786


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')