CVE-2025-52968

Public on 2025-06-23
Modified on 2025-06-25
Description
xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, associate x-scheme-handler/https with the execution of a browser with command-line options that arrange for an empty cookie store, although this would add substantial complexity, and would not be considered a desirable or expected behavior by all users.) NOTE: this is disputed because integrations of xdg-open typically do not provide information about whether the xdg-open command and arguments were manually entered by a user, or whether they were the result of a navigation from content in an untrusted origin.
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
2.7
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core xdg-utils Pending Fix
Amazon Linux 2023 xdg-utils Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 2.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
NVD CVSSv3 2.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N