Cross-site Request Forgery (CSRF) Affecting qutebrowser package, versions [,1.4.1)


0.0
high

Snyk CVSS

    Attack Complexity Low
    User Interaction Required
    Confidentiality High
    Integrity High
    Availability High

    Threat Intelligence

    EPSS 0.2% (57th percentile)
Expand this section
NVD
8.8 high

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-PYTHON-QUTEBROWSER-1657080
  • published 22 Sep 2021
  • disclosed 10 Oct 2018
  • credit toofar

How to fix?

Upgrade qutebrowser to version 1.4.1 or higher.

Overview

qutebrowser is a keyboard-driven, vim-like browser based on PyQt5.

Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF). This may be exploited to cause websites to access qute://* URLS. Furthermore, a malicious actor could exploit this to load a qute://settings/set URL, which sets editor.command to a bash script, resulting in arbitrary code execution.