An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the domnodenormalize function
{ "urgency": "not yet assigned" }