CVE-2026-41526

EUVD-2026-26004
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
kdekcoreaddons
𝑥
< 6.25.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
kcoreaddons
bookworm
vulnerable
bullseye
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
kf6-kcoreaddons
forky
vulnerable
sid
vulnerable
trixie
vulnerable
Azure Linux logo
Azure Linux Releases
Azure Package
Release
kf-kcoreaddons
Azure Linux 3.0
0:5.249.0-2.azl3
fixed