CVE-2026-41525 Details
Description
KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of the FileManager1 protocol allows the path given to be any type of file, including scripts or executables. (By default, Dolphin will then prompt the user to determine if they want to launch a script or executable; however, the intended behavior is to block the attempted action, not present a consent prompt.)
A vulnerability in KDE Dolphin versions prior to 25.12.3 allows applications in a Flatpak or with AppArmor confinement to access folders outside of their designated sandbox. This issue arises from Dolphin's handling of the FileManager1 protocol, which can be exploited to open scripts or executables without proper oversight. While Dolphin typically prompts users before executing such files, the expected behavior is to block these actions altogether.
Users can update to KDE Dolphin version 25.12.3 or later. Alternatively, the vulnerability can be addressed by applying a specific patch available in the KDE Dolphin GitLab repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-669 | Incorrect Resource Transfer Between Spheres | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | CVE Modified | CVE |
| Apr 28, 2026 | New CVE Received | [email protected] |