PT-2026-26624 · Python · Cpython

Seth Larson

·

Published

2026-03-20

·

Updated

2026-03-20

·

CVE-2026-4519

CVSS v4.0

7.0

High

AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

Fix

Related Identifiers

CVE-2026-4519

Affected Products

Cpython