Updated cantata and qutebrowser packages has been released for Arch Linux:
ASA-201806-12: cantata: multiple issuesThe package cantata before version 2.3.1-2 is vulnerable to multiple issues including access restriction bypass and privilege escalation.
ASA-201806-13: qutebrowser: cross-site scriptingThe package qutebrowser before version 1.3.3-1 is vulnerable to cross-site scripting.