CVE-2017-17516: Injection Vulnerability
(updated )
scripts/inspect_webbrowser.py
in Reddit Terminal Viewer (RTV) does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
References
Detect and mitigate CVE-2017-17516 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →