cbcvebase.
CVE-2025-52968
published 2025-06-23

CVE-2025-52968: xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified…

PriorityP49low2.7CVSS 3.1
AVLACHPRNUIRSCCLINAN
EPSS
0.18%
8.2th percentile
xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, associate x-scheme-handler/https with the execution of a browser with command-line options that arrange for an empty cookie store, although this would add substantial complexity, and would not be considered a desirable or expected behavior by all users.) NOTE: this is disputed because integrations of xdg-open typically do not provide information about whether the xdg-open command and arguments were manually entered by a user, or whether they were the result of a navigation from content in an untrusted origin.

Affected

2 ranges
VendorProductVersion rangeFixed in
debianxdg-utils
freedesktopxdg-utils<= 1.2.1

CVSS provenance

nvdv3.12.7LOWCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
osv2.7LOW
vendor_debian2.7LOW
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.