{"id":"PSF-0000-CVE-2026-4786","details":"Mitgation of CVE-2026-4519 was incomplete. If the URL contained \"%action\" the mitigation could be bypassed for certain browser types the \"webbrowser.open()\" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.","aliases":["BIT-libpython-2026-4786","BIT-python-2026-4786","BIT-python-min-2026-4786","CVE-2026-4786","PSF-2026-17"],"modified":"2026-07-06T16:11:34.044103030Z","published":"2026-04-13T21:52:19.036Z","database_specific":{"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/python/cpython/pull/148170"},{"type":"REPORT","url":"https://github.com/python/cpython/issues/148169"},{"type":"ADVISORY","url":"https://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/python/cpython","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-0000-CVE-2026-4786.json"}}],"schema_version":"1.7.5"}