Qutebrowser CSRF Vulnerability
High severity
GitHub Reviewed
Published
Oct 10, 2018
to the GitHub Advisory Database
•
Updated Oct 16, 2024
Description
Published to the GitHub Advisory Database
Oct 10, 2018
Reviewed
Jun 16, 2020
Last updated
Oct 16, 2024
qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access
qute://*
URLs. A malicious website could exploit this to load aqute://settings/set
URL, which then setseditor.command
to a bash script, resulting in arbitrary code execution.References