वीकनेस
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
संदर्भ
- https://github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53
- https://github.com/python/cpython/commit/a4d3edf3a6ecfde504d02126410d2a65a859b744
- https://github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca
- https://github.com/python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fff
- https://github.com/python/cpython/commit/d6d68494be70bdbda20f89f83801ba52ec37daa4
- https://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।