Cookie Management Flaw in xdg-open of xdg-utils by FreeDesktop
CVE-2025-52968
What is CVE-2025-52968?
A potential vulnerability exists in the xdg-open component of xdg-utils through version 1.2.1. This flaw allows for the sending of requests that include SameSite=Strict cookies. While there is contention surrounding this issue, it is crucial to note that the underlying integrations of xdg-open do not typically disclose whether commands and arguments are entered by the user or originate from an untrusted source. This ambiguity raises concerns regarding the security of cookie management and could lead to CSRF attacks if not properly mitigated.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
xdg-utils 0 <= 1.2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
