{"id":"ECHO-39bc-1319-217c","summary":"xdg-open launching a browser with a URL can cause SameSite=Strict cookies to be\nsent (browser treats it like typed navigation). The CVE record itself notes this\nis disputed: integrations of xdg-open typically do not convey whether the command\nwas manually entered by the user, and distro/browser vendors treat mitigation as a\nbrowser CLI/\"untrusted URL\" concern rather than an xdg-utils code defect.\nDebian rates the issue unimportant and has no fixed version in any suite (including\nforky/sid). No upstream patch exists in xdg-utils; oss-security discussion (2025-06-23)\nrecommended browser-side untrusted-mode flags first.\n","modified":"2026-07-19T16:15:05.465146407Z","published":"2026-02-09T12:00:58.397063Z","withdrawn":"2026-07-19T15:45:03.512Z","upstream":["CVE-2025-52968"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2025-52968"}],"affected":[{"package":{"name":"xdg-utils","ecosystem":"Echo","purl":"pkg:deb/echo/xdg-utils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.1-2+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-39bc-1319-217c.json"}}],"schema_version":"1.9.0"}