Remote command execution In pypy3
Description
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel9 | 0:3.14.5-1.el9_8 | ||
rpm rhel9.6 | 0:3.9.21-2.el9_6.6 | ||
rpm rhel10.0 | 0:3.12.9-2.el10_0.9 | ||
rpm rhel9.6 | 0:3.11.11-2.el9_6.7 | ||
debian 14 | 7.3.22+dfsg-1 | ||
debian 14 | 3.13.14-1 | ||
debian 14 | 3.14.5-1 | ||
rpm rhel9.6 | 0:3.12.9-1.el9_6.8 | ||
rpm rhel6 | - | - | |
rpm rhel8 | 0:3.6.8-76.el8_10 |
1-10 of 31
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24. 25. 26. 27. 28. 29. 30. 31. 32. 33. 34. 35. 36. 37. 38. 39. 40. 41. 42. 43. 44. 45. 46. 47. 48. 49. 50. 51. 52. 53. 54. 55. 56. 57. 58.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.