HIGH8.8
PYSEC-2026-914
Reddit Terminal Viewer (RTV) vulnerable to argument injection attacks
Details
scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/rtv
Introduced in:
0No fixed version published yet for rtv (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-17516[ADVISORY]
- https://github.com/michael-lazar/rtv/issues/531[WEB]
- https://github.com/michael-lazar/rtv[PACKAGE]
- https://security-tracker.debian.org/tracker/CVE-2017-17516[WEB]
- https://pypi.org/project/rtv[PACKAGE]
- https://github.com/advisories/GHSA-336h-q7mh-8vf8[ADVISORY]