CPython webbrowser.open() Leading-Dash URL Injection in 3.15
CVE-2026-4519 Published on March 20, 2026
webbrowser.open() allows leading dashes in URLs
The webbrowser.open() API would accept leading dashes in the URL which
could be handled as command line options for certain web browsers. New
behavior rejects leading dashes. Users are recommended to sanitize URLs
prior to passing to webbrowser.open().
Vulnerability Analysis
CVE-2026-4519 can be exploited with network access, requires user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and a small impact on availability.
Weakness Types
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
What is an Argument Injection Vulnerability?
The software constructs a string for a command to executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
CVE-2026-4519 has been classified to as an Argument Injection vulnerability or weakness.
Products Associated with CVE-2026-4519
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-4519 are published in these products:
Affected Versions
Python Software Foundation CPython:- Before 3.13.13 is affected.
- Version 3.14.0 and below 3.14.4 is affected.
- Version 3.15.0a1 and below 3.15.0a8 is affected.
- Version 0:3.12.12-3.el10_1.2 and below * is unaffected.
- Version 0:3.12.13-2.el10_2 and below * is unaffected.
- Version 0:3.14.4-2.el10_2 and below * is unaffected.
- Version 0:3.12.9-2.el10_0.8 and below * is unaffected.
- Version 0:2.6.6-70.el6_10.3 and below * is unaffected.
- Version 0:2.7.5-94.el7_9.4 and below * is unaffected.
- Version 0:3.6.8-21.el7_9.5 and below * is unaffected.
- Version 0:3.11.13-6.el8_10 and below * is unaffected.
- Version 0:3.12.12-4.el8_10 and below * is unaffected.
- Version 0:3.6.8-75.el8_10 and below * is unaffected.
- Version 0:3.6.8-24.el8_2.7 and below * is unaffected.
- Version 0:3.6.8-39.el8_4.10 and below * is unaffected.
- Version 0:3.6.8-39.el8_4.10 and below * is unaffected.
- Version 0:3.6.8-47.el8_6.12 and below * is unaffected.
- Version 0:3.6.8-47.el8_6.12 and below * is unaffected.
- Version 0:3.6.8-47.el8_6.12 and below * is unaffected.
- Version 0:3.6.8-51.el8_8.14 and below * is unaffected.
- Version 0:3.11.2-2.el8_8.9 and below * is unaffected.
- Version 0:3.6.8-51.el8_8.14 and below * is unaffected.
- Version 0:3.11.2-2.el8_8.9 and below * is unaffected.
- Version 0:3.11.13-5.2.el9_7 and below * is unaffected.
- Version 0:3.11.13-9.el9_8 and below * is unaffected.
- Version 0:3.14.4-2.el9_8 and below * is unaffected.
- Version 0:3.12.12-4.el9_7.2 and below * is unaffected.
- Version 0:3.12.13-2.el9_8 and below * is unaffected.
- Version 0:3.9.25-3.el9_7.2 and below * is unaffected.
- Version 0:3.9.25-7.el9_8 and below * is unaffected.
- Version 0:3.9.10-4.el9_0.10 and below * is unaffected.
- Version 0:3.11.2-2.el9_2.11 and below * is unaffected.
- Version 0:3.9.16-1.el9_2.13 and below * is unaffected.
- Version 0:3.9.18-3.el9_4.12 and below * is unaffected.
- Version 0:3.12.1-4.el9_4.12 and below * is unaffected.
- Version 0:3.11.7-1.el9_4.12 and below * is unaffected.
- Version 0:3.12.9-1.el9_6.7 and below * is unaffected.
- Version 0:3.9.21-2.el9_6.5 and below * is unaffected.
- Version 0:3.11.11-2.el9_6.6 and below * is unaffected.
- Version 7.13.5-4.1777325677 and below * is unaffected.
- Version 7.13.5-4.1777325711 and below * is unaffected.
- Version 7.13.5-4.1777325710 and below * is unaffected.
- Version 7.13.5-3.1777325680 and below * is unaffected.
- Version 7.13.5-4.1777325709 and below * is unaffected.
- Version 7.13.5-4.1777325680 and below * is unaffected.
- Version 7.13.5-4.1777325708 and below * is unaffected.
- Version 1775740563 and below * is unaffected.
- Version 1779223654 and below * is unaffected.
- Version 1779223651 and below * is unaffected.
- Version 1780681984 and below * is unaffected.
- Version 1775749857 and below * is unaffected.
- Version 1778244559 and below * is unaffected.
- Version 1775680262 and below * is unaffected.
- Version 1778244531 and below * is unaffected.
- Version 1775680192 and below * is unaffected.
- Version 1778274666 and below * is unaffected.
- Version 1778244546 and below * is unaffected.
- Version 1775668717 and below * is unaffected.
- Version 1776871984 and below * is unaffected.
- Version 1776871985 and below * is unaffected.
- Version 1776872005 and below * is unaffected.
- Version 1776773390 and below * is unaffected.
- Version 1776871987 and below * is unaffected.
- Version 1776773505 and below * is unaffected.
- Version 1776938871 and below * is unaffected.
- Version 3.11.15-2.hum1 and below * is unaffected.
- Version 3.12.13-2.hum1 and below * is unaffected.
- Version 3.13.13-1.hum1 and below * is unaffected.
- Version 3.14.4-1.hum1 and below * is unaffected.
- Version 1776868774 and below * is unaffected.
- Version 1779798159 and below * is unaffected.
- Version 1776868744 and below * is unaffected.
- Version 1779798164 and below * is unaffected.
- Version 1776868772 and below * is unaffected.
- Version 1779798165 and below * is unaffected.
- Version 1776868842 and below * is unaffected.
- Version 1779798222 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.