The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL.
{ "urgency": "medium" }
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2008-3907.json"