{"id":"CVE-2026-57501","summary":"Zen: Context-menu \"Open link in glance\" / \"Split link in new tab\" loads a page-controlled link with the System principal, bypassing the web-content scheme restriction","details":"Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load a page-controlled link URL with the System principal instead of the originating page's principal, allowing a malicious web page to place a link to a file URL that can load with System privileges when opened through either context-menu item and bypass the content-to-file security check that blocks an ordinary click. This issue is fixed in version 1.21.5b.","aliases":["GHSA-vpvg-hp3v-rm5q"],"modified":"2026-07-15T01:49:03.348342997Z","published":"2026-07-09T22:27:34.962Z","database_specific":{"cwe_ids":["CWE-266"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57501.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/zen-browser/desktop/releases/tag/1.21.5b"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57501.json"},{"type":"ADVISORY","url":"https://github.com/zen-browser/desktop/security/advisories/GHSA-vpvg-hp3v-rm5q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57501"},{"type":"FIX","url":"https://github.com/zen-browser/desktop/commit/44f7616238208200547c7df500d945752d7b6379"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zen-browser/desktop","events":[{"introduced":"0"},{"fixed":"44f7616238208200547c7df500d945752d7b6379"},{"fixed":"a685738db4456d11a19d5845157722db3888888c"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.21.5b"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.21.4b","1.21.3b","1.21.2b","1.21.1b","1.21b","1.20.2b","1.20.1b","1.20b","1.19.13b","1.19.12b","1.19.11b","1.19.10b","1.19.9b","1.19.8b","1.19.7b","1.19.6b","1.19.5b","1.19.4b","1.19.3b","1.19.2b","1.19.1b","1.19b","1.18.10b","twilight-1","1.18.9b","1.18.7b","1.18.6b","1.18.5b","1.18.4b","1.18.3b","1.18.2b","1.18.1b","1.18b","1.17.15b","1.17.14b","1.17.13b","1.17.12b","1.17.11b","1.17.10b","1.17.9b","1.17.8b","1.17.7b","1.17.6b","1.17.5b","1.17.3b","1.17.2b","1.17.1b","1.16.4b","1.16.3b","1.16.1b","1.16b","1.15.5b","1.15.4b","1.15.3b","1.15.2b","1.14.11b","1.14.10b","1.14.9b","1.14.8b","1.14.6b","1.14.5b","1.14.4b","1.14.3b","1.14.2b","1.14.1b","1.14b","1.13.2b","1.13.1b","1.13b","1.12.10b","1.12.9b","1.12.8b","1.12.7b","1.12.6b","1.12.5b","1.12.4b","1.12.3b","1.12.2b","1.12b","1.11.5b","1.11.4b","1.11.1b","1.11b","1.10.3b","1.10b","1.9b","1.8.2b","1.8.1b","1.8b","1.7.6b","1.7.4b","1.7.3b","1.7.2b","1.7.1b","1.7b","1.6b","1.0.2-b.5","1.0.2-b.4","1.0.2-b.3","1.0.2-b.2","1.0.2-b.1","1.0.2-b.0","1.0.1-a.19","1.0.1-a.21","1.0.1-a.20","1.0.1-a.18","1.0.1-a.17","1.0.1-a.16","1.0.1-a.15","1.0.1-a.14","1.0.1-a.13","1.0.1-a.12","1.0.1-a.11","1.0.1-a.10","1.0.1-a.9","1.0.1-a.8","1.0.1-a.7","1.0.1-a.6","1.0.1-a.5","1.0.1-a.4","1.0.1-a.3","1.0.1-a.2","1.0.1-a.1","1.0.0-a.39","1.0.0-a.35","1.0.0-a.34","1.0.0-a.33","1.0.0-a.32","1.0.0-a.31","1.0.0-a.30","1.0.0-a.29","1.0.0-a.27","1.0.0-a.26","1.0.0-a.24","1.0.0-a.23","1.0.0-a.16","1.0.0-a.15","1.0.0-a.14","1.0.0-a.13","1.0.0-a.12","1.0.0-a.11","1.0.0-a.10","1.0.0-a.9","1.0.0-a.8","1.0.0-a.7","1.0.0-a.6","1.0.0-a.5","1.0.0-a.4","1.0.0-a.3","1.0.0-a.2","1.0.0-a.1","0.0.0-a.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57501.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N"}]}