webbrowser
Rust library to open URLs in the web browsers available on a platform
Activity
- Latest release
- 1mo ago
- Total releases
- 45
- Cadence
- ~42 days
- Last 12 months
- 7
Reach
- Downloads
- 40.8M
- Stars
- 327
Details
- License
- MIT OR Apache-2.0
- First release
- Dec 08, 2015
| Version | Released | |
|---|---|---|
1.2.4
patch
|
1.2.4
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.2.3
patch
|
1.2.3
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.2.2
patch
|
1.2.2
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.2.1
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
1.2.1
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.2.0
minor
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
1.2.0
minor
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.1.0
minor
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
1.1.0
minor
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.0.6
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
1.0.6
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.0.5
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
1.0.5
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.0.4
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
1.0.4
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.0.3
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
1.0.3
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.0.2
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
1.0.2
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.0.1
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
1.0.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.0.0
major
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
1.0.0
major
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.15
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.15
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.14
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.14
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.13
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.13
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.12
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.12
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.11
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.11
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.10
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.10
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.9
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.9
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.8
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.8
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.7
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.7
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.6
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.6
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.5
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.5
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.4
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.4
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.8.3
patch
1 CVE
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev |
0.8.3
patch
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
0.8.2
patch
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.8.2
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.8.1
patch
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.8.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.8.0
minor
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.8.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.7.1
patch
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.7.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.7.0
minor
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.7.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.6.0
minor
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev |
0.6.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.5.5
patch
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.5.4
patch
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.5.3
patch
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.5.2
patch
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.5.1
patch
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.5.0
minor
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.4.0
minor
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.3.1
patch
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.3.0
minor
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.2
patch
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.1
minor
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.1.3
patch
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
0.1.2
initial
2 CVEs
RUSTSEC-2026-0257
GHSA-2ph8-5cr8-hr33
Jul 29, 2026
Unix `BROWSER` handling allows browser argument injection On Unix platforms handled by The issue was reproduced with Chromium by injecting
Version 1.2.2 fixes the issue by tokenizing the This issue was reported by @dywzju09-blip. Fixed in
1.2.2
References
Updated Aug 12, 2026 · Source: OSV.dev
CVE-2022-45299
GHSA-m589-mv4q-p7rj
Jan 13, 2023
webbrowser-rs allows attackers to access arbitrary files via supplying a crafted URL
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL. Fixed in
0.8.3
References Updated Nov 08, 2023 · Source: OSV.dev |