Report: CVE-2026-4519 - webbrowser.open() allows leading dashes in URLs

Report: CVE-2026-4519 - webbrowser.open() allows leading dashes in URLs

CVE ID :CVE-2026-4519 Published : March 20, 2026, 3:16 p.m. | 56 minutes ago Description :The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open(). Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
March 20, 2026