{"id":"DEBIAN-CVE-2026-41526","details":"In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \\x01 can be used during injection.","modified":"2026-09-14T17:03:34.836659567Z","published":"2026-04-28T08:16:01.647Z","upstream":["CVE-2026-41526"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-41526"}],"affected":[{"package":{"name":"kcoreaddons","ecosystem":"Debian:12","purl":"pkg:deb/debian/kcoreaddons?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.103.0-1","5.104.0-1","5.107.0-1","5.115.0-1","5.115.0-2","5.116.0-1","5.116.0-2","5.116.0-3","5.116.0-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41526.json"}},{"package":{"name":"kcoreaddons","ecosystem":"Debian:13","purl":"pkg:deb/debian/kcoreaddons?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.116.0-1","5.116.0-2","5.116.0-3","5.116.0-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41526.json"}},{"package":{"name":"kcoreaddons","ecosystem":"Debian:14","purl":"pkg:deb/debian/kcoreaddons?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.116.0-2"}]}],"versions":["5.116.0-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41526.json"}},{"package":{"name":"kf6-kcoreaddons","ecosystem":"Debian:13","purl":"pkg:deb/debian/kf6-kcoreaddons?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.13.0-1","6.18.0-1","6.18.0-2","6.20.0-1","6.23.0-1","6.23.0-2","6.26.0-1","6.26.0-2","6.26.0-3","6.28.0-1","6.28.0-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41526.json"}},{"package":{"name":"kf6-kcoreaddons","ecosystem":"Debian:14","purl":"pkg:deb/debian/kf6-kcoreaddons?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.26.0-1"}]}],"versions":["6.13.0-1","6.18.0-1","6.18.0-2","6.20.0-1","6.23.0-1","6.23.0-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-41526.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}