From ${URL} : A Debian user reported a different command injection issue recently, and proposed a patch too: https://bugs.debian.org/cgi-bin/bugreport.cgi?msg=5;filename=xdg-open.diff;att=1;bug=777722 Seems to do with local variable usage that isn't really local. For more detail, see: https://bugs.debian.org/777722 @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
In 1.1.1 xdg-open has been reworked to be safer, and I cannot reproduce test case. It's being stabilised in bug #558676.
GLSA Vote: No Arches and Maintainer(s), Thank you for your work.