CVE-2026-41525
Last modified
CVE-2026-41525 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of the FileManager1 protocol allows the path given to be any type of file, including scripts or executables. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of the FileManager1 protocol allows the path given to be any type of file, including scripts or executables. (By default, Dolphin will then prompt the user to determine if they want to launch a script or executable; however, the intended behavior is to block the attempted action, not present a consent prompt.)
Metrics
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| KDE | Dolphin | < 25.12.3 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-41525?
How severe is CVE-2026-41525?
How do I fix CVE-2026-41525?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4152GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code…7.8
- CVE-2026-41520Cilium is a networking, observability, and security solution…4.4
- CVE-2026-41521xrdp is an open source RDP server. Versions 0.10.6 and prior…9.1
- CVE-2026-41522Iris is a web collaborative platform that helps incident res…7.1
- CVE-2026-41523vLLM is an inference and serving engine for large language m…7.5
- CVE-2026-41524Brave CMS is an open-source CMS. Prior to commit 6c56603, pa…8.7
- CVE-2026-41526In KDE KCoreAddons before 6.25, KShell::quoteArgs is intende…7.8
- CVE-2026-41527KDE Kleopatra before 26.08.0 on Windows allows local users t…6.9
- CVE-2026-4153GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code…7.8
- CVE-2026-41530The automatic folder creation feature of Lhaz and Lhaz+ prov…4.6
- CVE-2026-41539A cross-site scripting (XSS) vulnerability has been reported…6.1
- CVE-2026-4154GIMP XPM File Parsing Integer Overflow Remote Code Execution…7.8
Are you affected by CVE-2026-41525?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
