Which is not on its own a "vulnerability", you'd need to chain it to something usable in the browser / as a consequence of the browser being opened.
It increases your options, certainly, but it can't do anything dangerous as-is.
It increases your options, certainly, but it can't do anything dangerous as-is.
You could execute a 'curl` which directly pipes into 'bash -c'.
See https://github.com/python/cpython/blob/master/Lib/webbrowser...