Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8509-1 Python vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:10117 cve-icon
https://access.redhat.com/errata/RHSA-2026:10140 cve-icon
https://access.redhat.com/errata/RHSA-2026:10141 cve-icon
https://access.redhat.com/errata/RHSA-2026:10711 cve-icon
https://access.redhat.com/errata/RHSA-2026:10745 cve-icon
https://access.redhat.com/errata/RHSA-2026:10774 cve-icon
https://access.redhat.com/errata/RHSA-2026:10949 cve-icon
https://access.redhat.com/errata/RHSA-2026:10950 cve-icon
https://access.redhat.com/errata/RHSA-2026:11062 cve-icon
https://access.redhat.com/errata/RHSA-2026:11077 cve-icon
https://access.redhat.com/errata/RHSA-2026:11768 cve-icon
https://access.redhat.com/errata/RHSA-2026:13692 cve-icon
https://access.redhat.com/errata/RHSA-2026:13812 cve-icon
https://access.redhat.com/errata/RHSA-2026:14652 cve-icon
https://access.redhat.com/errata/RHSA-2026:14653 cve-icon
https://access.redhat.com/errata/RHSA-2026:14656 cve-icon
https://access.redhat.com/errata/RHSA-2026:16699 cve-icon
https://access.redhat.com/errata/RHSA-2026:17525 cve-icon
https://access.redhat.com/errata/RHSA-2026:17619 cve-icon
https://access.redhat.com/errata/RHSA-2026:19019 cve-icon
https://access.redhat.com/errata/RHSA-2026:19064 cve-icon
https://access.redhat.com/errata/RHSA-2026:19175 cve-icon
https://access.redhat.com/errata/RHSA-2026:19176 cve-icon
https://access.redhat.com/errata/RHSA-2026:19177 cve-icon
https://access.redhat.com/errata/RHSA-2026:19216 cve-icon
https://access.redhat.com/errata/RHSA-2026:19549 cve-icon
https://access.redhat.com/errata/RHSA-2026:19570 cve-icon
https://access.redhat.com/errata/RHSA-2026:19571 cve-icon
https://access.redhat.com/errata/RHSA-2026:19576 cve-icon
https://access.redhat.com/errata/RHSA-2026:19589 cve-icon
https://access.redhat.com/errata/RHSA-2026:19590 cve-icon
https://access.redhat.com/errata/RHSA-2026:21275 cve-icon
https://access.redhat.com/errata/RHSA-2026:21682 cve-icon
https://access.redhat.com/errata/RHSA-2026:22144 cve-icon
https://access.redhat.com/errata/RHSA-2026:25096 cve-icon
https://access.redhat.com/errata/RHSA-2026:26187 cve-icon
https://access.redhat.com/errata/RHSA-2026:28247 cve-icon
https://access.redhat.com/errata/RHSA-2026:28581 cve-icon
https://access.redhat.com/errata/RHSA-2026:30078 cve-icon
https://access.redhat.com/errata/RHSA-2026:30087 cve-icon
https://access.redhat.com/errata/RHSA-2026:30088 cve-icon
https://access.redhat.com/errata/RHSA-2026:30089 cve-icon
https://access.redhat.com/errata/RHSA-2026:35838 cve-icon
https://access.redhat.com/errata/RHSA-2026:8822 cve-icon
https://access.redhat.com/errata/RHSA-2026:8824 cve-icon
https://access.redhat.com/errata/RHSA-2026:9228 cve-icon
https://access.redhat.com/security/cve/CVE-2026-4786 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2458049 cve-icon
https://github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53 cve-icon cve-icon
https://github.com/python/cpython/commit/a4d3edf3a6ecfde504d02126410d2a65a859b744 cve-icon cve-icon
https://github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca cve-icon cve-icon
https://github.com/python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fff cve-icon cve-icon
https://github.com/python/cpython/commit/d6d68494be70bdbda20f89f83801ba52ec37daa4 cve-icon cve-icon
https://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769 cve-icon cve-icon
https://github.com/python/cpython/issues/148169 cve-icon cve-icon cve-icon
https://github.com/python/cpython/pull/148170 cve-icon cve-icon cve-icon
https://mail.python.org/archives/list/[email protected]/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/ cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-4786 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4786.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-4786 cve-icon
History

Wed, 05 Aug 2026 01:00:00 +0000


Wed, 29 Apr 2026 16:15:00 +0000


Wed, 15 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-88
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Tue, 14 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Python
Python cpython
Vendors & Products Python
Python cpython

Tue, 14 Apr 2026 15:00:00 +0000


Tue, 14 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Apr 2026 22:00:00 +0000

Type Values Removed Values Added
Description Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Title Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: PSF

Published:

Updated: 2026-08-13T00:27:20.638Z

Reserved: 2026-03-24T19:25:48.269Z

Link: CVE-2026-4786

cve-icon Vulnrichment

Updated: 2026-07-15T00:48:45.183Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-13T22:16:30.413

Modified: 2026-08-13T01:16:54.237

Link: CVE-2026-4786

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-13T21:52:19Z

Links: CVE-2026-4786 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T15:45:07Z

Weaknesses