{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "1.21.5b"
              }
            ],
            "source": [
              "AFFECTED_FIELD",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "44f7616238208200547c7df500d945752d7b6379"
            },
            {
              "fixed": "a685738db4456d11a19d5845157722db3888888c"
            }
          ],
          "repo": "https://github.com/zen-browser/desktop",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-vpvg-hp3v-rm5q"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-266"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57501.json"
  },
  "details": "Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance and Split link in new tab, load a page-controlled link URL with the System principal instead of the originating page's principal, allowing a malicious web page to place a link to a file URL that can load with System privileges when opened through either context-menu item and bypass the content-to-file security check that blocks an ordinary click. This issue is fixed in version 1.21.5b.",
  "id": "CVE-2026-57501",
  "modified": "2026-07-15T01:49:03.348342997Z",
  "published": "2026-07-09T22:27:34.962Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/zen-browser/desktop/releases/tag/1.21.5b"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57501.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/zen-browser/desktop/security/advisories/GHSA-vpvg-hp3v-rm5q"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-57501"
    },
    {
      "type": "FIX",
      "url": "https://github.com/zen-browser/desktop/commit/44f7616238208200547c7df500d945752d7b6379"
    }
  ],
  "schema_version": "1.8.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Zen: Context-menu \"Open link in glance\" / \"Split link in new tab\" loads a page-controlled link with the System principal, bypassing the web-content scheme restriction"
}