qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access qute://* URLs. A malicious website could exploit this to load a qute://settings/set URL, which then sets editor.command to a bash script, resulting in arbitrary code execution.
{
"severity": "HIGH",
"cwe_ids": [
"CWE-352"
],
"nvd_published_at": null,
"github_reviewed_at": "2020-06-16T22:00:28Z",
"github_reviewed": true
}