PT-2026-57005 · Zen · Zen

CVE-2026-57501

·

Published

2026-07-09

·

Updated

2026-07-10

CVSS v3.1

0.0

None

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zen versions prior to 1.21.5b
Description In the glance and split-view context-menu actions, specifically Open link in glance and Split link in new tab, the browser loads a page-controlled link URL using the System principal instead of the originating page's principal. This allows a malicious web page to create a link to a file URL that loads with System privileges when accessed via these context-menu items, bypassing the content-to-file security check that normally blocks standard clicks.
Recommendations Update Zen to version 1.21.5b.

Exploit

Fix

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57501
GHSA-VPVG-HP3V-RM5Q

Affected Products

Zen