CVE-2026-41525
MEDIUMDescription
KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of the FileManager1 protocol allows the path given to be any type of file, including scripts or executables. (By default, Dolphin will then prompt the user to determine if they want to launch a script or executable; however, the intended behavior is to block the attempted action, not present a consent prompt.)
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-41525? +
How severe is CVE-2026-41525? +
How do I check if I'm vulnerable to CVE-2026-41525? +
Related Vulnerabilities
mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the …
Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable …
Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if …
An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that …
Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides …
Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.