xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, associate x-scheme-handler/https with the execution of a browser with command-line options that arrange for an empty cookie store, although this would add substantial complexity, and would not be considered a desirable or expected behavior by all users.) NOTE: this is disputed because integrations of xdg-open typically do not provide information about whether the xdg-open command and arguments were manually entered by a user, or whether they were the result of a navigation from content in an untrusted origin.
CVSS Details
- CVSS 3.1 Base Score: 2.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | no-fix-debian-deb-package | Jun 25, 2025 | Jun 23, 2025 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Jun 23, 2025 | |
| Ubuntu | no-fix-ubuntu-package | Jul 9, 2025 | Jun 23, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub