Python CPython "webbrowser.open" "%action" URL injection (CVE-2026-4786)
CVE-2026-4786 Published on April 13, 2026
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Vulnerability Analysis
CVE-2026-4786 is exploitable with network access, requires user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and a small impact on availability.
Weakness Types
What is a Command Injection Vulnerability?
The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVE-2026-4786 has been classified to as a Command Injection vulnerability or weakness.
What is an Argument Injection Vulnerability?
The software constructs a string for a command to executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
CVE-2026-4786 has been classified to as an Argument Injection vulnerability or weakness.
Products Associated with CVE-2026-4786
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-4786 are published in these products:
Affected Versions
Python Software Foundation CPython:- Before 3.13.14 is affected.
- Version 3.14.0a1 and below 3.14.5rc1 is affected.
- Version 3.15.0a1 and below 3.15.0b1 is affected.
- Version 0:3.12.12-3.el10_1.3 and below * is unaffected.
- Version 0:3.12.13-2.el10_2 and below * is unaffected.
- Version 0:3.14.4-2.el10_2 and below * is unaffected.
- Version 0:3.14.5-1.el10_2 and below * is unaffected.
- Version 0:3.12.9-2.el10_0.9 and below * is unaffected.
- Version 0:2.6.6-70.el6_10.4 and below * is unaffected.
- Version 0:2.7.5-94.el7_9.5 and below * is unaffected.
- Version 0:3.6.8-21.el7_9.6 and below * is unaffected.
- Version 0:3.12.13-2.el8_10 and below * is unaffected.
- Version 0:3.11.13-7.el8_10 and below * is unaffected.
- Version 0:3.6.8-76.el8_10 and below * is unaffected.
- Version 0:3.6.8-39.el8_4.11 and below * is unaffected.
- Version 0:3.6.8-39.el8_4.11 and below * is unaffected.
- Version 0:3.6.8-47.el8_6.13 and below * is unaffected.
- Version 0:3.6.8-47.el8_6.13 and below * is unaffected.
- Version 0:3.6.8-47.el8_6.13 and below * is unaffected.
- Version 0:3.6.8-51.el8_8.15 and below * is unaffected.
- Version 0:3.11.2-2.el8_8.10 and below * is unaffected.
- Version 0:3.6.8-51.el8_8.15 and below * is unaffected.
- Version 0:3.11.2-2.el8_8.10 and below * is unaffected.
- Version 0:3.12.12-4.el9_7.3 and below * is unaffected.
- Version 0:3.12.13-2.el9_8 and below * is unaffected.
- Version 0:3.11.13-5.3.el9_7 and below * is unaffected.
- Version 0:3.11.13-9.el9_8 and below * is unaffected.
- Version 0:3.9.25-3.el9_7.3 and below * is unaffected.
- Version 0:3.9.25-7.el9_8 and below * is unaffected.
- Version 0:3.14.4-2.el9_8 and below * is unaffected.
- Version 0:3.14.5-1.el9_8 and below * is unaffected.
- Version 0:3.9.10-4.el9_0.11 and below * is unaffected.
- Version 0:3.11.2-2.el9_2.12 and below * is unaffected.
- Version 0:3.9.16-1.el9_2.14 and below * is unaffected.
- Version 0:3.11.7-1.el9_4.13 and below * is unaffected.
- Version 0:3.12.1-4.el9_4.13 and below * is unaffected.
- Version 0:3.9.18-3.el9_4.13 and below * is unaffected.
- Version 0:3.11.11-2.el9_6.7 and below * is unaffected.
- Version 0:3.12.9-1.el9_6.8 and below * is unaffected.
- Version 0:3.9.21-2.el9_6.6 and below * is unaffected.
- Version 7.13.5-4.1777325677 and below * is unaffected.
- Version 7.13.5-4.1777325711 and below * is unaffected.
- Version 7.13.5-4.1777325710 and below * is unaffected.
- Version 7.13.5-3.1777325680 and below * is unaffected.
- Version 7.13.5-4.1777325709 and below * is unaffected.
- Version 7.13.5-4.1777325680 and below * is unaffected.
- Version 7.13.5-4.1777325708 and below * is unaffected.
- Version 1780681984 and below * is unaffected.
- Version 1782352950 and below * is unaffected.
- Version 1782352919 and below * is unaffected.
- Version 1782353093 and below * is unaffected.
- Version 1782352847 and below * is unaffected.
- Version 1776871984 and below * is unaffected.
- Version 1776871985 and below * is unaffected.
- Version 1776872005 and below * is unaffected.
- Version 1776773390 and below * is unaffected.
- Version 1776871987 and below * is unaffected.
- Version 1776773505 and below * is unaffected.
- Version 1776938871 and below * is unaffected.
- Version 3.13.13-1.1.hum1 and below * is unaffected.
- Version 3.11.15-4.hum1 and below * is unaffected.
- Version 3.12.13-3.hum1 and below * is unaffected.
- Version 3.14.4-2.hum1 and below * is unaffected.
- Version 1777459441 and below * is unaffected.
- Version 1777454300 and below * is unaffected.
- Version 1777459504 and below * is unaffected.
- Version 1779798159 and below * is unaffected.
- Version 1779798164 and below * is unaffected.
- Version 1779798165 and below * is unaffected.
- Version 1779798222 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.