{"id":"CVE-2026-41526","details":"In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \\x01 can be used during injection.","modified":"2026-08-12T08:43:41.335585Z","published":"2026-04-28T00:00:00Z","related":["openSUSE-SU-2026:20701-1"],"database_specific":{"cna_assigner":"mitre","cwe_ids":["CWE-150"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41526.json"},"references":[{"type":"WEB","url":"https://github.com/KDE/kcoreaddons/blob/50d360736c399502fedf203e95482b0d0e5a3ea2/src/lib/util/kshell.h#L168"},{"type":"WEB","url":"https://github.com/KDE/kcoreaddons/blob/50d360736c399502fedf203e95482b0d0e5a3ea2/src/lib/util/kshell.h#L43-L49"},{"type":"WEB","url":"https://github.com/KDE/kcoreaddons/releases/tag/v6.25.0"},{"type":"WEB","url":"https://invent.kde.org/frameworks/kcoreaddons/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41526.json"},{"type":"ADVISORY","url":"https://kde.org/info/security/advisory-20260427-1.txt"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41526"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kde/kcoreaddons","events":[{"introduced":"0"},{"fixed":"447250fb061d6a866eeef9ae3c21b627244b198a"}],"database_specific":{"cpe":"cpe:2.3:a:kde:kcoreaddons:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"6.25"},{"fixed":"6.25.0"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"]}}],"versions":["v6.24.0-rc1","v6.24.0","v6.25.0-rc1","v6.23.0-rc1","v6.23.0","v6.22.0-rc1","v6.22.0","v6.21.0-rc1","v6.21.0","v6.20.0-rc1","v6.20.0","v6.19.0-rc1","v6.19.0","v6.18.0-rc1","v6.18.0","v6.17.0-rc1","v6.17.0","v6.16.0-rc1","v6.15.0-rc1","v6.15.0","v6.14.0-rc1","v6.14.0","v6.13.0-rc1","v6.13.0","v6.12.0-rc1","v6.12.0","v6.11.0-rc1","v6.11.0","v6.10.0-rc1","v6.10.0","v6.9.0-rc1","v6.9.0","v6.8.0-rc1","v6.8.0","v6.7.0-rc1","v6.7.0","v6.6.0-rc1","v6.6.0","v6.5.0-rc1","v6.5.0","v6.4.0-rc1","v6.4.0","v6.3.0-rc1","v6.3.0","v6.2.0","v6.1.0","v6.0.0","v5.249.0","v5.248.0","v5.247.0","v5.246.0","v5.245.0","v5.102.0-rc1","v5.102.0","v5.101.0-rc1","v5.101.0","v5.100.0-rc1","v5.100.0","v5.71.0-rc1","v5.58.0-rc2","v4.100.0-rc1","v4.98.0","v4.97.0","v4.96.0","v4.95.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41526.json","vanir_signatures_modified":"2026-08-12T08:43:41Z","vanir_signatures":[{"target":{"file":"autotests/kshelltest.cpp"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["101242747992186653511417093557509794467","289492607933053574148690065154341894781","198140037164833794255906943454151045957","75387108103848991872040299280887139000","74876094864197514540435824269514909788","186445428269008507085100123106181500447","11689821127377195628528302445792716321","52191208206242672580547876533996239307"]},"id":"CVE-2026-41526-2a0ed2b1","signature_type":"Line","signature_version":"v1","source":"https://github.com/kde/kcoreaddons/commit/447250fb061d6a866eeef9ae3c21b627244b198a"},{"source":"https://github.com/kde/kcoreaddons/commit/447250fb061d6a866eeef9ae3c21b627244b198a","target":{"function":"KShellTest::splitJoin","file":"autotests/kshelltest.cpp"},"deprecated":false,"digest":{"function_hash":"269699193607117156218673488905848151047","length":3005},"id":"CVE-2026-41526-2bb3b016","signature_type":"Function","signature_version":"v1"},{"digest":{"function_hash":"210308155905021240217803383337848224490","length":1124},"id":"CVE-2026-41526-808d6cfe","signature_type":"Function","signature_version":"v1","source":"https://github.com/kde/kcoreaddons/commit/447250fb061d6a866eeef9ae3c21b627244b198a","target":{"file":"autotests/kshelltest.cpp","function":"KShellTest::quoteArg"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["225639946299247260451457028093073383910","58389281763611245987394164797044294048","333172051205955134080879410972295025039","214713120480125572592113733239610938803","243844166672824801946868297242642501986","73369659960717528809488638970620368949","309925860393492931049031522512095779755","16222956159584201209915227067866342453","115167371515695717789286540627059728240","115228852714762316445054894050089439209","115050677378497909640628784778660171937"],"threshold":0.9},"id":"CVE-2026-41526-dd5db4a1","signature_type":"Line","signature_version":"v1","source":"https://github.com/kde/kcoreaddons/commit/447250fb061d6a866eeef9ae3c21b627244b198a","target":{"file":"src/lib/util/kshell_unix.cpp"}},{"id":"CVE-2026-41526-f79652d6","signature_type":"Function","signature_version":"v1","source":"https://github.com/kde/kcoreaddons/commit/447250fb061d6a866eeef9ae3c21b627244b198a","target":{"file":"src/lib/util/kshell_unix.cpp","function":"KShell::quoteArg"},"deprecated":false,"digest":{"length":351,"function_hash":"55846286754143926611966765158088947234"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L"}]}