{"id":"CVE-2017-17516","aliases":["GHSA-336h-q7mh-8vf8","PYSEC-2026-914"],"title":"Reddit Terminal Viewer (RTV) vulnerable to argument injection attacks","summary":"Reddit Terminal Viewer (RTV) vulnerable to argument injection attacks","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","vendor":"rtv","product":"rtv","ecosystem":"pip","affected":["rtv <= 1.19.0"],"published":"2022-05-14","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-336h-q7mh-8vf8","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-17516"},{"url":"https://github.com/michael-lazar/rtv/issues/531"},{"url":"https://github.com/michael-lazar/rtv"},{"url":"https://security-tracker.debian.org/tracker/CVE-2017-17516"}],"tags":["osv","pip"],"epss":0.01179,"epssPercentile":0.6583,"ingestedAt":"2026-07-08T18:25:44.654Z","slug":"CVE-2017-17516","body":"## Overview\n\nscripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.\n\n## Affected packages\n\n- `rtv <= 1.19.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}