VDB
EN

RUSTSEC-2026-0257

Unix `BROWSER` handling allows browser argument injection

상세

On Unix platforms handled by `src/unix.rs`, affected versions substitute the caller-supplied URL into the `BROWSER` environment-variable template before tokenizing the resulting string with `split_ascii_whitespace()`. If an application passes an attacker-controlled non-HTTP(S) URL whose parsed form retains spaces and the effective `BROWSER` template contains `%s`, text that should remain within one URL argument becomes additional browser arguments.

The issue was reproduced with Chromium by injecting `--remote-debugging-port`, which exposed a local DevTools endpoint, and `--proxy-server`, which redirected browser traffic through an attacker-controlled proxy. The available arguments and resulting impact depend on the browser launched by the affected application.

Version 1.2.2 fixes the issue by tokenizing the `BROWSER` template before substituting the URL, preserving the URL as part of a single argument. Users should upgrade to version 1.2.2 or later. Applications that only need HTTP(S) URLs can also enable the crate's `hardened` feature as defense in depth.

This issue was reported by [@dywzju09-blip](https://github.com/dywzju09-blip).

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

crates.io / webbrowser
최초 영향 버전: 0.0.0-0 수정 버전: 1.2.2

Upgrade webbrowser to 1.2.2 or newer (ecosystem crates.io).

참고