CVE-2026-4519Improper Input Validation in Software Foundation Cpython

Severity
7.0HIGHNVD
EPSS
0.0%
top 90.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateApr 13

Description

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Packages1 packages

CVEListV5python_software_foundation/cpython3.14.03.14.4+3

🔴Vulnerability Details

3
CVEList
webbrowser.open() allows leading dashes in URLs2026-03-20
GHSA
GHSA-rm92-fj5q-mpj5: The webbrowser2026-03-20
OSV
CVE-2026-4519: The webbrowser2026-03-20

📋Vendor Advisories

4
Red Hat
python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API2026-04-13
Red Hat
python: Python: Command-line option injection in webbrowser.open() via crafted URLs2026-03-20
Microsoft
webbrowser.open() allows leading dashes in URLs2026-03-10
Debian
CVE-2026-4519: jython - The webbrowser.open() API would accept leading dashes in the URL which could be...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-4519 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

5
Bugzilla
CVE-2026-4786 python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API2026-04-13
Bugzilla
CVE-2026-4519 python3.15: Python: Command-line option injection in webbrowser.open() via crafted URLs [fedora-all]2026-03-20
Bugzilla
CVE-2026-4519 python: Python: Command-line option injection in webbrowser.open() via crafted URLs2026-03-20
Bugzilla
CVE-2026-4519 python3.13: Python: Command-line option injection in webbrowser.open() via crafted URLs [epel-all]2026-03-20
Bugzilla
CVE-2026-4519 mingw-python3: Python: Command-line option injection in webbrowser.open() via crafted URLs [fedora-all]2026-03-20
CVE-2026-4519 — Improper Input Validation | cvebase