🔐 CVE Alert

CVE-2026-4786

UNKNOWN 0.0

Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
5th

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CWE CWE-77
Vendor python software foundation
Product cpython
Published Apr 13, 2026
Last Updated Apr 14, 2026
Stay Ahead of the Next One

Get instant alerts for python software foundation cpython

Be the first to know when new unknown vulnerabilities affecting python software foundation cpython are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Python Software Foundation / CPython
0 < 3.15.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/python/cpython/pull/148170 github.com: https://github.com/python/cpython/issues/148169 mail.python.org: https://mail.python.org/archives/list/[email protected]/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/ github.com: https://github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca github.com: https://github.com/python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fff github.com: https://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769

Credits

🔍 an7y Seth Larson Stan Ulbrych