Vulnerability Details CVE-2026-41526
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to handle user input are affected and could be exploited. In particular, because sendInput() sends a string to a terminal, a control character such as \x01 can be used during injection.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 2.8%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-41526
-
cpe:2.3:a:kde:kcoreaddons:4.100.0
-
cpe:2.3:a:kde:kcoreaddons:4.95.0
-
cpe:2.3:a:kde:kcoreaddons:4.96.0
-
cpe:2.3:a:kde:kcoreaddons:4.97.0
-
cpe:2.3:a:kde:kcoreaddons:4.98.0
-
cpe:2.3:a:kde:kcoreaddons:4.99.0
-
cpe:2.3:a:kde:kcoreaddons:5.0.0
-
cpe:2.3:a:kde:kcoreaddons:5.1.0
-
cpe:2.3:a:kde:kcoreaddons:5.10.0
-
cpe:2.3:a:kde:kcoreaddons:5.100.0
-
cpe:2.3:a:kde:kcoreaddons:5.101.0
-
cpe:2.3:a:kde:kcoreaddons:5.102.0
-
cpe:2.3:a:kde:kcoreaddons:5.103.0
-
cpe:2.3:a:kde:kcoreaddons:5.104.0
-
cpe:2.3:a:kde:kcoreaddons:5.105.0
-
cpe:2.3:a:kde:kcoreaddons:5.106.0
-
cpe:2.3:a:kde:kcoreaddons:5.107.0
-
cpe:2.3:a:kde:kcoreaddons:5.108.0
-
cpe:2.3:a:kde:kcoreaddons:5.109.0
-
cpe:2.3:a:kde:kcoreaddons:5.11.0
-
cpe:2.3:a:kde:kcoreaddons:5.110.0
-
cpe:2.3:a:kde:kcoreaddons:5.111.0
-
cpe:2.3:a:kde:kcoreaddons:5.112.0
-
cpe:2.3:a:kde:kcoreaddons:5.113.0
-
cpe:2.3:a:kde:kcoreaddons:5.114.0
-
cpe:2.3:a:kde:kcoreaddons:5.115.0
-
cpe:2.3:a:kde:kcoreaddons:5.116.0
-
cpe:2.3:a:kde:kcoreaddons:5.12.0
-
cpe:2.3:a:kde:kcoreaddons:5.13.0
-
cpe:2.3:a:kde:kcoreaddons:5.14.0
-
cpe:2.3:a:kde:kcoreaddons:5.15.0
-
cpe:2.3:a:kde:kcoreaddons:5.16.0
-
cpe:2.3:a:kde:kcoreaddons:5.17.0
-
cpe:2.3:a:kde:kcoreaddons:5.18.0
-
cpe:2.3:a:kde:kcoreaddons:5.19.0
-
cpe:2.3:a:kde:kcoreaddons:5.2.0
-
cpe:2.3:a:kde:kcoreaddons:5.20.0
-
cpe:2.3:a:kde:kcoreaddons:5.21.0
-
cpe:2.3:a:kde:kcoreaddons:5.22.0
-
cpe:2.3:a:kde:kcoreaddons:5.23.0
-
cpe:2.3:a:kde:kcoreaddons:5.24.0
-
cpe:2.3:a:kde:kcoreaddons:5.245.0
-
cpe:2.3:a:kde:kcoreaddons:5.246.0
-
cpe:2.3:a:kde:kcoreaddons:5.247.0
-
cpe:2.3:a:kde:kcoreaddons:5.248.0
-
cpe:2.3:a:kde:kcoreaddons:5.249.0
-
cpe:2.3:a:kde:kcoreaddons:5.25.0
-
cpe:2.3:a:kde:kcoreaddons:5.26.0
-
cpe:2.3:a:kde:kcoreaddons:5.27.0
-
cpe:2.3:a:kde:kcoreaddons:5.28.0
-
cpe:2.3:a:kde:kcoreaddons:5.29.0
-
cpe:2.3:a:kde:kcoreaddons:5.3.0
-
cpe:2.3:a:kde:kcoreaddons:5.30.0
-
cpe:2.3:a:kde:kcoreaddons:5.30.1
-
cpe:2.3:a:kde:kcoreaddons:5.31.0
-
cpe:2.3:a:kde:kcoreaddons:5.32.0
-
cpe:2.3:a:kde:kcoreaddons:5.33.0
-
cpe:2.3:a:kde:kcoreaddons:5.34.0
-
cpe:2.3:a:kde:kcoreaddons:5.35.0
-
cpe:2.3:a:kde:kcoreaddons:5.36.0
-
cpe:2.3:a:kde:kcoreaddons:5.37.0
-
cpe:2.3:a:kde:kcoreaddons:5.38.0
-
cpe:2.3:a:kde:kcoreaddons:5.39.0
-
cpe:2.3:a:kde:kcoreaddons:5.4.0
-
cpe:2.3:a:kde:kcoreaddons:5.40.0
-
cpe:2.3:a:kde:kcoreaddons:5.41.0
-
cpe:2.3:a:kde:kcoreaddons:5.42.0
-
cpe:2.3:a:kde:kcoreaddons:5.43.0
-
cpe:2.3:a:kde:kcoreaddons:5.44.0
-
cpe:2.3:a:kde:kcoreaddons:5.45.0
-
cpe:2.3:a:kde:kcoreaddons:5.46.0
-
cpe:2.3:a:kde:kcoreaddons:5.47.0
-
cpe:2.3:a:kde:kcoreaddons:5.48.0
-
cpe:2.3:a:kde:kcoreaddons:5.49.0
-
cpe:2.3:a:kde:kcoreaddons:5.5.0
-
cpe:2.3:a:kde:kcoreaddons:5.50.0
-
cpe:2.3:a:kde:kcoreaddons:5.51.0
-
cpe:2.3:a:kde:kcoreaddons:5.52.0
-
cpe:2.3:a:kde:kcoreaddons:5.53.0
-
cpe:2.3:a:kde:kcoreaddons:5.53.1
-
cpe:2.3:a:kde:kcoreaddons:5.54.0
-
cpe:2.3:a:kde:kcoreaddons:5.55.0
-
cpe:2.3:a:kde:kcoreaddons:5.56.0
-
cpe:2.3:a:kde:kcoreaddons:5.57.0
-
cpe:2.3:a:kde:kcoreaddons:5.58.0
-
cpe:2.3:a:kde:kcoreaddons:5.59.0
-
cpe:2.3:a:kde:kcoreaddons:5.6.0
-
cpe:2.3:a:kde:kcoreaddons:5.60.0
-
cpe:2.3:a:kde:kcoreaddons:5.61.0
-
cpe:2.3:a:kde:kcoreaddons:5.62.0
-
cpe:2.3:a:kde:kcoreaddons:5.63.0
-
cpe:2.3:a:kde:kcoreaddons:5.64.0
-
cpe:2.3:a:kde:kcoreaddons:5.65.0
-
cpe:2.3:a:kde:kcoreaddons:5.66.0
-
cpe:2.3:a:kde:kcoreaddons:5.67.0
-
cpe:2.3:a:kde:kcoreaddons:5.68.0
-
cpe:2.3:a:kde:kcoreaddons:5.69.0
-
cpe:2.3:a:kde:kcoreaddons:5.7.0
-
cpe:2.3:a:kde:kcoreaddons:5.70.0
-
cpe:2.3:a:kde:kcoreaddons:5.71.0
-
cpe:2.3:a:kde:kcoreaddons:5.72.0
-
cpe:2.3:a:kde:kcoreaddons:5.73.0
-
cpe:2.3:a:kde:kcoreaddons:5.74.0
-
cpe:2.3:a:kde:kcoreaddons:5.75.0
-
cpe:2.3:a:kde:kcoreaddons:5.76.0
-
cpe:2.3:a:kde:kcoreaddons:5.77.0
-
cpe:2.3:a:kde:kcoreaddons:5.78.0
-
cpe:2.3:a:kde:kcoreaddons:5.79.0
-
cpe:2.3:a:kde:kcoreaddons:5.8.0
-
cpe:2.3:a:kde:kcoreaddons:5.80.0
-
cpe:2.3:a:kde:kcoreaddons:5.81.0
-
cpe:2.3:a:kde:kcoreaddons:5.82.0
-
cpe:2.3:a:kde:kcoreaddons:5.83.0
-
cpe:2.3:a:kde:kcoreaddons:5.84.0
-
cpe:2.3:a:kde:kcoreaddons:5.85.0
-
cpe:2.3:a:kde:kcoreaddons:5.86.0
-
cpe:2.3:a:kde:kcoreaddons:5.87.0
-
cpe:2.3:a:kde:kcoreaddons:5.88.0
-
cpe:2.3:a:kde:kcoreaddons:5.89.0
-
cpe:2.3:a:kde:kcoreaddons:5.9.0
-
cpe:2.3:a:kde:kcoreaddons:5.90.0
-
cpe:2.3:a:kde:kcoreaddons:5.91.0
-
cpe:2.3:a:kde:kcoreaddons:5.92.0
-
cpe:2.3:a:kde:kcoreaddons:5.93.0
-
cpe:2.3:a:kde:kcoreaddons:5.94.0
-
cpe:2.3:a:kde:kcoreaddons:5.95.0
-
cpe:2.3:a:kde:kcoreaddons:5.96.0
-
cpe:2.3:a:kde:kcoreaddons:5.97.0
-
cpe:2.3:a:kde:kcoreaddons:5.98.0
-
cpe:2.3:a:kde:kcoreaddons:5.99.0
-
cpe:2.3:a:kde:kcoreaddons:6.0.0
-
cpe:2.3:a:kde:kcoreaddons:6.1.0
-
cpe:2.3:a:kde:kcoreaddons:6.10.0
-
cpe:2.3:a:kde:kcoreaddons:6.11.0
-
cpe:2.3:a:kde:kcoreaddons:6.12.0
-
cpe:2.3:a:kde:kcoreaddons:6.13.0
-
cpe:2.3:a:kde:kcoreaddons:6.14.0
-
cpe:2.3:a:kde:kcoreaddons:6.15.0
-
cpe:2.3:a:kde:kcoreaddons:6.16.0
-
cpe:2.3:a:kde:kcoreaddons:6.17.0
-
cpe:2.3:a:kde:kcoreaddons:6.18.0
-
cpe:2.3:a:kde:kcoreaddons:6.19.0
-
cpe:2.3:a:kde:kcoreaddons:6.2.0
-
cpe:2.3:a:kde:kcoreaddons:6.20.0
-
cpe:2.3:a:kde:kcoreaddons:6.21.0
-
cpe:2.3:a:kde:kcoreaddons:6.22.0
-
cpe:2.3:a:kde:kcoreaddons:6.23.0
-
cpe:2.3:a:kde:kcoreaddons:6.24.0
-
cpe:2.3:a:kde:kcoreaddons:6.3.0
-
cpe:2.3:a:kde:kcoreaddons:6.4.0
-
cpe:2.3:a:kde:kcoreaddons:6.5.0
-
cpe:2.3:a:kde:kcoreaddons:6.6.0
-
cpe:2.3:a:kde:kcoreaddons:6.7.0
-
cpe:2.3:a:kde:kcoreaddons:6.8.0
-
cpe:2.3:a:kde:kcoreaddons:6.9.0