Due to a CSRF vulnerability affecting the qute://settings page, it was possible for websites to modify qutebrowser settings. Via settings like 'editor.command', this possibly allowed websites to execute arbitrary code.
Due to a CSRF vulnerability affecting the qute://settings page, it was possible for websites to modify qutebrowser settings. Via settings like 'editor.command', this possibly allowed websites to execute arbitrary code.
https://github.com/qutebrowser/qutebrowser/commit/43e58ac865ff862c2008c510fc5f7627e10b4660 https://github.com/qutebrowser/qutebrowser/issues/4060