Lucene search

K
osvGoogleOSV:GHSA-WGMX-52PH-QQCW
HistoryOct 10, 2018 - 4:05 p.m.

Qutebrowser CSRF Vulnerability

2018-10-1016:05:23
Google
osv.dev
4

0.002 Low

EPSS

Percentile

57.3%

qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access qute://* URLs. A malicious website could exploit this to load a qute://settings/set URL, which then sets editor.command to a bash script, resulting in arbitrary code execution.