{"id":"CVE-2018-1000559","aliases":["GHSA-m4fw-77v7-924m","PYSEC-2018-26"],"url":"https://o3.security/vulnerability/CVE-2018-1000559","summary":"Qutebrowser XSS Vulnerability","details":"qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript code, a website can steal the user's browsing history. This attack appear to be exploitable via the victim must open a page with a specially crafted <title> attribute, and then open the qute://history site via the :history command. This vulnerability appears to have been fixed in fixed in v1.3.3 (4c9360237f186681b1e3f2a0f30c45161cf405c7, to be released today) and v1.4.0 (5a7869f2feaa346853d2a85413d6527c87ef0d9f, released later this week).","published":"2018-06-26T16:29:02.930Z","modified":"2026-07-08T12:29:01.686976Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"qutebrowser","fixedVersion":"1.3.3"}],"fix":{"url":"https://github.com/qutebrowser/qutebrowser/commit/4c9360237f186681b1e3f2a0f30c45161cf405c7","label":"qutebrowser/qutebrowser@4c93602"},"references":[{"type":"FIX","url":"https://github.com/qutebrowser/qutebrowser/commit/4c9360237f186681b1e3f2a0f30c45161cf405c7"},{"type":"FIX","url":"https://github.com/qutebrowser/qutebrowser/commit/5a7869f2feaa346853d2a85413d6527c87ef0d9f"},{"type":"EVIDENCE","url":"https://github.com/qutebrowser/qutebrowser/issues/4011"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:29:01.686976Z"}}