Cross-site Scripting (XSS) Affecting qutebrowser package, versions <1.3.3-1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.12% (48th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DEBIAN12-QUTEBROWSER-1558596
  • published26 Jun 2018
  • disclosed26 Jun 2018

Introduced: 26 Jun 2018

CVE-2018-1000559  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade Debian:12 qutebrowser to version 1.3.3-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream qutebrowser package and not the qutebrowser package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript code, a website can steal the user's browsing history. This attack appear to be exploitable via the victim must open a page with a specially crafted <title> attribute, and then open the qute://history site via the :history command. This vulnerability appears to have been fixed in fixed in v1.3.3 (4c9360237f186681b1e3f2a0f30c45161cf405c7, to be released today) and v1.4.0 (5a7869f2feaa346853d2a85413d6527c87ef0d9f, released later this week).