CVE-2021-41146
published 2021-10-21CVE-2021-41146: qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.45%
70.4th percentile
qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially crafted `qutebrowserurl:...` URL can lead to execution of qutebrowser commands, which in turn allows arbitrary code execution via commands such as `:spawn` or `:debug-pyeval`. Only Windows installs where qutebrowser is registered as URL handler are affected. The issue has been fixed in qutebrowser v2.4.0. The fix also adds additional hardening for potential similar issues on Linux (by adding the new --untrusted-args flag to the .desktop file), though no such vulnerabilities are known.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qutebrowser | — | — |
| qutebrowser | qutebrowser | <= 1.7.0 | — |
| qutebrowser | qutebrowser | — | — |
| qutebrowser | qutebrowser | >= 0 < 8f46ba3f6dc7b18375f7aa63c48a1fe461190430 | 8f46ba3f6dc7b18375f7aa63c48a1fe461190430 |
| qutebrowser | qutebrowser | >= 0 < 1.8.0 | 1.8.0 |
| qutebrowser | qutebrowser | >= 1.7.0 < 2.4.0 | 2.4.0 |
| qutebrowser | qutebrowser | >= 2.0.0 < 2.4.0 | 2.4.0 |
| qutebrowser | qutebrowser | >= 2.0.0 < 2.4.0 | 2.4.0 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian8.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Arbitrary command execution on Windows via qutebrowserurl: URL handler
ghsa·2021-10-22
CVE-2021-41146 [HIGH] CWE-641 Arbitrary command execution on Windows via qutebrowserurl: URL handler
Arbitrary command execution on Windows via qutebrowserurl: URL handler
### Impact
Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers it as a handler for certain URL schemes. With some applications such as Outlook Desktop, opening a specially crafted URL can lead to argument injection, allowing execution of qutebrowser commands, which in turn allows arbitrary code execution via commands such as `:spawn` or `:debug-pyeval`.
Only Windows installs where qutebrowser is registered as URL handler are affected. It does *not* have to be set as default browser for the exploit to work.
### Patches
The issue has been fixed in [qutebrowser v2.4.0](https://github.com/qutebrowser/qutebrowser/releases/tag/v2.4.0) in commit 8f46ba3f6dc7b18375f7aa63c48a1fe461190430.
The fi
OSV
Arbitrary command execution on Windows via qutebrowserurl: URL handler
osv·2021-10-22
CVE-2021-41146 [HIGH] Arbitrary command execution on Windows via qutebrowserurl: URL handler
Arbitrary command execution on Windows via qutebrowserurl: URL handler
### Impact
Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers it as a handler for certain URL schemes. With some applications such as Outlook Desktop, opening a specially crafted URL can lead to argument injection, allowing execution of qutebrowser commands, which in turn allows arbitrary code execution via commands such as `:spawn` or `:debug-pyeval`.
Only Windows installs where qutebrowser is registered as URL handler are affected. It does *not* have to be set as default browser for the exploit to work.
### Patches
The issue has been fixed in [qutebrowser v2.4.0](https://github.com/qutebrowser/qutebrowser/releases/tag/v2.4.0) in commit 8f46ba3f6dc7b18375f7aa63c48a1fe461190430.
The fi
OSV
CVE-2021-41146: qutebrowser is an open source keyboard-focused browser with a minimal GUI
osv·2021-10-21
CVE-2021-41146 CVE-2021-41146: qutebrowser is an open source keyboard-focused browser with a minimal GUI
qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially crafted `qutebrowserurl:...` URL can lead to execution of qutebrowser commands, which in turn allows arbitrary code execution via commands such as `:spawn` or `:debug-pyeval`. Only Windows installs where qutebrowser is registered as URL handler are affected. The issue has been fixed in qutebrowser v2.4.0. The fix also adds additional hardening for potential similar issues on Linux (by adding the new --untrusted-args flag to the .desktop file), though no such vulnerabilities are known.
Debian
CVE-2021-41146: qutebrowser - qutebrowser is an open source keyboard-focused browser with a minimal GUI. Start...
vendor_debian·2021·CVSS 8.8
CVE-2021-41146 [HIGH] CVE-2021-41146: qutebrowser - qutebrowser is an open source keyboard-focused browser with a minimal GUI. Start...
qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially crafted `qutebrowserurl:...` URL can lead to execution of qutebrowser commands, which in turn allows arbitrary code execution via commands such as `:spawn` or `:debug-pyeval`. Only Windows installs where qutebrowser is registered as URL handler are affected. The issue has been fixed in qutebrowser v2.4.0. The fix also adds additional hardening for potential similar issues on Linux (by adding the new --untrusted-args flag to the .desktop file), though no such vulnerabilities are known.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: r
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/qutebrowser/qutebrowser/commit/8f46ba3f6dc7b18375f7aa63c48a1fe461190430https://github.com/qutebrowser/qutebrowser/security/advisories/GHSA-vw27-fwjf-5qxmhttps://github.com/qutebrowser/qutebrowser/commit/8f46ba3f6dc7b18375f7aa63c48a1fe461190430https://github.com/qutebrowser/qutebrowser/security/advisories/GHSA-vw27-fwjf-5qxm
2021-10-21
Published