Skip to content
appaloosa scout logo main rounded
LOW 3.3

CVE-2026-4519

The webbrowser.open() API would accept leading dashes in the URL which
could be handled as command line options for certain web browsers. New
behavior rejects leading dashes. Users are recommended to sanitize URLs
prior to passing to webbrowser.open().

CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS 0.0% percentile 0.9%

Affected tracked apps

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
python python Windows <3.13.13 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows ≥3.14.0 <3.14.4 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.15.0:alpha3:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.15.0:alpha4:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.15.0:alpha5:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.15.0:alpha6:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.15.0:alpha7:*:*:*:*:*:*
View on NVD ↗