ECHO-39bc-1319-217c

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-39bc-1319-217c.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-39bc-1319-217c
Upstream
Withdrawn
2026-07-19T15:45:03Z
Published
2026-02-09T12:00:58Z
Modified
2026-07-19T16:15:05Z
Summary
xdg-open launching a browser with a URL can cause SameSite=Strict cookies to be sent (browser treats it like typed navigation). The CVE record itself notes this is disputed: integrations of xdg-open typically do not convey whether the command was manually entered by the user, and distro/browser vendors treat mitigation as a browser CLI/"untrusted URL" concern rather than an xdg-utils code defect. Debian rates the issue unimportant and has no fixed version in any suite (including forky/sid). No upstream patch exists in xdg-utils; oss-security discussion (2025-06-23) recommended browser-side untrusted-mode flags first.
Details
References

Affected packages

Echo / xdg-utils

Package

Name
xdg-utils
Purl
pkg:deb/echo/xdg-utils

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.1-2+e1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-39bc-1319-217c.json"