{"id":"ECHO-39bc-1319-217c","upstream":["CVE-2025-52968"],"severity":[],"modified":"2026-07-19T15:45:03.512Z","affected":[{"package":{"ecosystem":"Echo","name":"xdg-utils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.1-2+e1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2025-52968"}],"withdrawn":"2026-07-19T15:45:03.512Z","summary":"xdg-open launching a browser with a URL can cause SameSite=Strict cookies to be\nsent (browser treats it like typed navigation). The CVE record itself notes this\nis disputed: integrations of xdg-open typically do not convey whether the command\nwas manually entered by the user, and distro/browser vendors treat mitigation as a\nbrowser CLI/\"untrusted URL\" concern rather than an xdg-utils code defect.\nDebian rates the issue unimportant and has no fixed version in any suite (including\nforky/sid). No upstream patch exists in xdg-utils; oss-security discussion (2025-06-23)\nrecommended browser-side untrusted-mode flags first.\n"}