---
id: CVE-2026-57501
title: Zen is a firefox-based browser
summary: >-
  Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view
  context-menu actions, Open link in glance and Split link in new tab, load a
  page-controlled link URL with the System principal instead of the originating
  page'…
severity: none
cvss: 0
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N'
cwe:
  - CWE-266
published: '2026-07-09'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57501'
references:
  - url: >-
      https://github.com/zen-browser/desktop/commit/44f7616238208200547c7df500d945752d7b6379
    label: security-advisories@github.com
  - url: 'https://github.com/zen-browser/desktop/releases/tag/1.21.5b'
    label: security-advisories@github.com
  - url: >-
      https://github.com/zen-browser/desktop/security/advisories/GHSA-vpvg-hp3v-rm5q
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00506
epssPercentile: 0.40553
ingestedAt: '2026-07-11T20:15:25.792Z'
---

## Overview

Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load a page-controlled link URL with the System principal instead of the originating page's principal, allowing a malicious web page to place a link to a file URL that can load with System privileges when opened through either context-menu item and bypass the content-to-file security check that blocks an ordinary click. This issue is fixed in version 1.21.5b.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
