File CVE-2026-4519-webbrowser-open-dashes.patch of Package python311
From 44f1cc679123978895a21b424ab9678bf86b4c78 Mon Sep 17 00:00:00 2001
From: Seth Michael Larson <seth@python.org>
Date: Fri, 20 Mar 2026 09:47:13 -0500
Subject: [PATCH] gh-143930: Reject leading dashes in webbrowser URLs
(cherry picked from commit 82a24a4442312bdcfc4c799885e8b3e00990f02b)
---
Lib/test/test_webbrowser.py | 5 +++
Lib/webbrowser.py | 14 ++++++++++
Misc/NEWS.d/next/Security/2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst | 1
3 files changed, 20 insertions(+)
create mode 100644 Misc/NEWS.d/next/Security/2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst
Index: Python-3.11.15/Lib/test/test_webbrowser.py
===================================================================
--- Python-3.11.15.orig/Lib/test/test_webbrowser.py 2026-03-27 20:08:53.792496478 +0100
+++ Python-3.11.15/Lib/test/test_webbrowser.py 2026-03-27 20:08:56.539400295 +0100
@@ -59,6 +59,11 @@
options=[],
arguments=[URL])
+ def test_reject_dash_prefixes(self):
+ browser = self.browser_class(name=CMD_NAME)
+ with self.assertRaises(ValueError):
+ browser.open(f"--key=val {URL}")
+
class BackgroundBrowserCommandTest(CommandTestMixin, unittest.TestCase):
Index: Python-3.11.15/Lib/webbrowser.py
===================================================================
--- Python-3.11.15.orig/Lib/webbrowser.py 2026-03-27 20:08:54.301026314 +0100
+++ Python-3.11.15/Lib/webbrowser.py 2026-03-27 20:08:56.539584483 +0100
@@ -154,6 +154,12 @@
def open_new_tab(self, url):
return self.open(url, 2)
+ @staticmethod
+ def _check_url(url):
+ """Ensures that the URL is safe to pass to subprocesses as a parameter"""
+ if url and url.lstrip().startswith("-"):
+ raise ValueError(f"Invalid URL: {url}")
+
class GenericBrowser(BaseBrowser):
"""Class for all browsers started with a command
@@ -171,6 +177,7 @@
def open(self, url, new=0, autoraise=True):
sys.audit("webbrowser.open", url)
+ self._check_url(url)
cmdline = [self.name] + [arg.replace("%s", url)
for arg in self.args]
try:
@@ -191,6 +198,7 @@
cmdline = [self.name] + [arg.replace("%s", url)
for arg in self.args]
sys.audit("webbrowser.open", url)
+ self._check_url(url)
try:
if sys.platform[:3] == 'win':
p = subprocess.Popen(cmdline)
@@ -256,6 +264,7 @@
def open(self, url, new=0, autoraise=True):
sys.audit("webbrowser.open", url)
+ self._check_url(url)
if new == 0:
action = self.remote_action
elif new == 1:
@@ -357,6 +366,7 @@
def open(self, url, new=0, autoraise=True):
sys.audit("webbrowser.open", url)
+ self._check_url(url)
# XXX Currently I know no way to prevent KFM from opening a new win.
if new == 2:
action = "newTab"
@@ -441,6 +451,7 @@
def open(self, url, new=0, autoraise=True):
sys.audit("webbrowser.open", url)
+ self._check_url(url)
if new:
ok = self._remote("LOADNEW " + url)
else:
@@ -604,6 +615,7 @@
class WindowsDefault(BaseBrowser):
def open(self, url, new=0, autoraise=True):
sys.audit("webbrowser.open", url)
+ self._check_url(url)
try:
os.startfile(url)
except OSError:
@@ -636,6 +648,7 @@
def open(self, url, new=0, autoraise=True):
sys.audit("webbrowser.open", url)
+ self._check_url(url)
assert "'" not in url
# hack for local urls
if not ':' in url:
@@ -688,6 +701,7 @@
def open(self, url, new=0, autoraise=True):
sys.audit("webbrowser.open", url)
+ self._check_url(url)
if self.name == 'default':
script = 'open location "%s"' % url.replace('"', '%22') # opens in default browser
else:
Index: Python-3.11.15/Misc/NEWS.d/next/Security/2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst
===================================================================
--- /dev/null 1970-01-01 00:00:00.000000000 +0000
+++ Python-3.11.15/Misc/NEWS.d/next/Security/2026-01-16-12-04-49.gh-issue-143930.zYC5x3.rst 2026-03-27 20:08:56.539850985 +0100
@@ -0,0 +1 @@
+Reject leading dashes in URLs passed to :func:`webbrowser.open`