QID 980808
QID 980808: Python (pip) Security Update for qutebrowser (GHSA-wgmx-52ph-qqcw)
qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, resulting in arbitrary code execution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-wgmx-52ph-qqcw for updates pertaining to this vulnerability.
Vendor References
- GHSA-wgmx-52ph-qqcw -
github.com/advisories/GHSA-wgmx-52ph-qqcw
CVEs related to QID 980808
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wgmx-52ph-qqcw | qutebrowser |
|