Description
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Published: 2026-04-13
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Command Injection leading to arbitrary code execution
Action: Immediate Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8509-1 Python vulnerabilities
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:10117 cve-icon
https://access.redhat.com/errata/RHSA-2026:10140 cve-icon
https://access.redhat.com/errata/RHSA-2026:10141 cve-icon
https://access.redhat.com/errata/RHSA-2026:10711 cve-icon
https://access.redhat.com/errata/RHSA-2026:10745 cve-icon
https://access.redhat.com/errata/RHSA-2026:10774 cve-icon
https://access.redhat.com/errata/RHSA-2026:10949 cve-icon
https://access.redhat.com/errata/RHSA-2026:10950 cve-icon
https://access.redhat.com/errata/RHSA-2026:11062 cve-icon
https://access.redhat.com/errata/RHSA-2026:11077 cve-icon
https://access.redhat.com/errata/RHSA-2026:11768 cve-icon
https://access.redhat.com/errata/RHSA-2026:13692 cve-icon
https://access.redhat.com/errata/RHSA-2026:13812 cve-icon
https://access.redhat.com/errata/RHSA-2026:14652 cve-icon
https://access.redhat.com/errata/RHSA-2026:14653 cve-icon
https://access.redhat.com/errata/RHSA-2026:14656 cve-icon
https://access.redhat.com/errata/RHSA-2026:16699 cve-icon
https://access.redhat.com/errata/RHSA-2026:17525 cve-icon
https://access.redhat.com/errata/RHSA-2026:17619 cve-icon
https://access.redhat.com/errata/RHSA-2026:19019 cve-icon
https://access.redhat.com/errata/RHSA-2026:19064 cve-icon
https://access.redhat.com/errata/RHSA-2026:19175 cve-icon
https://access.redhat.com/errata/RHSA-2026:19176 cve-icon
https://access.redhat.com/errata/RHSA-2026:19177 cve-icon
https://access.redhat.com/errata/RHSA-2026:19216 cve-icon
https://access.redhat.com/errata/RHSA-2026:19549 cve-icon
https://access.redhat.com/errata/RHSA-2026:19570 cve-icon
https://access.redhat.com/errata/RHSA-2026:19571 cve-icon
https://access.redhat.com/errata/RHSA-2026:19576 cve-icon
https://access.redhat.com/errata/RHSA-2026:19589 cve-icon
https://access.redhat.com/errata/RHSA-2026:19590 cve-icon
https://access.redhat.com/errata/RHSA-2026:21275 cve-icon
https://access.redhat.com/errata/RHSA-2026:21682 cve-icon
https://access.redhat.com/errata/RHSA-2026:22144 cve-icon
https://access.redhat.com/errata/RHSA-2026:25096 cve-icon
https://access.redhat.com/errata/RHSA-2026:26187 cve-icon
https://access.redhat.com/errata/RHSA-2026:28247 cve-icon
https://access.redhat.com/errata/RHSA-2026:28581 cve-icon
https://access.redhat.com/errata/RHSA-2026:30078 cve-icon
https://access.redhat.com/errata/RHSA-2026:30087 cve-icon
https://access.redhat.com/errata/RHSA-2026:30088 cve-icon
https://access.redhat.com/errata/RHSA-2026:30089 cve-icon
https://access.redhat.com/errata/RHSA-2026:35838 cve-icon
https://access.redhat.com/errata/RHSA-2026:8822 cve-icon
https://access.redhat.com/errata/RHSA-2026:8824 cve-icon
https://access.redhat.com/errata/RHSA-2026:9228 cve-icon
https://access.redhat.com/security/cve/CVE-2026-4786 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2458049 cve-icon
https://github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53 cve-icon cve-icon
https://github.com/python/cpython/commit/a4d3edf3a6ecfde504d02126410d2a65a859b744 cve-icon cve-icon
https://github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca cve-icon cve-icon
https://github.com/python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fff cve-icon cve-icon
https://github.com/python/cpython/commit/d6d68494be70bdbda20f89f83801ba52ec37daa4 cve-icon cve-icon
https://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769 cve-icon cve-icon
https://github.com/python/cpython/issues/148169 cve-icon cve-icon cve-icon
https://github.com/python/cpython/pull/148170 cve-icon cve-icon cve-icon
https://mail.python.org/archives/list/[email protected]/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/ cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-4786 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4786.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-4786 cve-icon
History

Wed, 05 Aug 2026 01:00:00 +0000


Wed, 29 Apr 2026 16:15:00 +0000


Wed, 15 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-88
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Tue, 14 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Python
Python cpython
Vendors & Products Python
Python cpython

Tue, 14 Apr 2026 15:00:00 +0000


Tue, 14 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Apr 2026 22:00:00 +0000

Type Values Removed Values Added
Description Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Title Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: PSF

Published:

Updated: 2026-08-13T00:27:20.638Z

Reserved: 2026-03-24T19:25:48.269Z

Link: CVE-2026-4786

cve-icon Vulnrichment

Updated: 2026-07-15T00:48:45.183Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-13T22:16:30.413

Modified: 2026-08-13T01:16:54.237

Link: CVE-2026-4786

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-13T21:52:19Z

Links: CVE-2026-4786 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T15:45:07Z

Weaknesses