This was addressed in https://usn.ubuntu.com/usn/usn-3650-1 and in xdg- utils 1.1.2-1ubuntu3 for cosmic. Thanks for the report!
** Changed in: xdg-utils (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1772295 Title: CVE-2017-18266: argument injection in xdg-open To manage notifications about this bug go to: https://bugs.launchpad.net/xdg-utils/+bug/1772295/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs