{"id":"AZL-85232","summary":"CVE-2026-41526 affecting package kf-kcoreaddons for versions less than 5.249.0-2","details":"In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \\x01 can be used during injection.","modified":"2026-08-30T05:26:50Z","published":"2026-04-28T08:16:01Z","upstream":["CVE-2026-41526"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41526"}],"affected":[{"package":{"name":"kf-kcoreaddons","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kf-kcoreaddons"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.249.0-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-85232.json"}}],"schema_version":"1.9.0"}