GHSA-vw27-fwjf-5qxm · Severity: high · Ecosystem: pip — Arbitrary command execution on Windows via qutebrowserurl: URL handler
qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially crafted `qutebrowserurl:...` URL can lead to execution of qutebrowser commands, which in turn allows arbitrary code execution via commands such as `:spawn` or `:debug-pyeval`. Only Windows installs where qutebrowser is registered as URL handler are affected. The issue has been fixed in qutebrowser v2.4.0. The fix also adds additional hardening for potential similar issues on Linux (by adding the new --untrusted-args flag to the .desktop file), though no such vulnerabilities are known.
Conclusion & alert: CVE-2021-41146 is rated Moderate Risk (60/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.74%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-02-18 | 1.36% | 0.74% | -0.62% |
| 2 | 2026-01-03 | 0.77% | 1.36% | +0.60% |
| 3 | 2025-11-21 | — | 0.77% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
GHSA-vw27-fwjf-5qxm · Severity: high · Ecosystem: pip — Arbitrary command execution on Windows via qutebrowserurl: URL handler
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2021-41146 unimportant priority: Debian including 1 source packages (qutebrowser), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-41146 |
ubuntu
|
medium | CVE-2021-41146 medium priority: Ubuntu including 1 source packages (qutebrowser), 8 status rows across 8 suites (bionic, focal, hirsute, impish, jammy, trusty, upstream, xenial): not-affected 6, ignored 2. | https://ubuntu.com/security/CVE-2021-41146 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| qutebrowser | qutebrowser | <= 1.7.0 | cpe:2.3:a:qutebrowser:qutebrowser:*:*:*:*:*:*:*:* |
| qutebrowser | qutebrowser | >= 2.0.0, < 2.4.0 | cpe:2.3:a:qutebrowser:qutebrowser:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/qutebrowser/qutebrowser/commit/8f46ba3f6dc7b18375f7aa63c48a1fe461190430 | Patch Third Party Advisory |
| https://github.com/qutebrowser/qutebrowser/security/advisories/GHSA-vw27-fwjf-5qxm | Third Party Advisory |