PT-2026-35678 · Kde · Kcoreaddons

·

CVE-2026-41526

·

Published

2026-04-28

·

Updated

2026-05-05

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KDE KCoreAddons versions prior to 6.25
Description The KShell::quoteArgs() function is designed to safely quote arguments for shell commands. However, it fails to adequately handle metacharacters, which can lead to a shell escape. Applications using this method in security-critical paths to process user input are susceptible. Specifically, since sendInput() transmits strings to a terminal, a control character such as x01 can be utilized during the injection process.
Recommendations Update to version 6.25 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41526
OPENSUSE-SU-2026:20701-1

Affected Products

Kcoreaddons