High severity8.8NVD Advisory· Published Dec 14, 2017· Updated May 13, 2026
CVE-2017-17522
CVE-2017-17522
Description
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that exploitation is impossible because the code relies on subprocess.Popen and the default shell=False setting
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/102207nvdThird Party AdvisoryVDB Entry
- security-tracker.debian.org/tracker/CVE-2017-17522nvdIssue TrackingThird Party Advisory
- bugs.python.org/issue32367nvd
News mentions
0No linked articles in our index yet.