CVE-2026-48700 Details
Description
An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution or circumvent network namespace restrictions. NOTE: those outcomes are potentially unwanted by most users; however, the behavior of the product does comply with the applicable specification, and a simplistic solution (ensuring that the URI does not name a regular file) may have adverse consequences for I/O.
A vulnerability exists in all versions of PCManFM-Qt starting from 1.1.0, related to the handling of file URIs through the D-Bus method org.freedesktop.FileManager1.ShowFolders. The application incorrectly assumes that all provided URIs are directories and delegates to external programs based on the file type without user confirmation. This behavior can lead to unintended code execution or allow users to circumvent network namespace restrictions, particularly when using Wine with its default MIME handlers for executable files.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 22, 2026CISA-ADP
Assessed May 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/24/6 | CVE | Mailing List |
| https://github.com/lxqt/pcmanfm-qt/releases | [email protected] | Release NotesVendor |
| https://www.openwall.com/lists/oss-security/2026/05/19/1 | [email protected] | Mailing ListTechnical Description |
| https://www.openwall.com/lists/oss-security/2026/05/20/2 | [email protected] | ExploitMailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-913 | Improper Control of Dynamically-Managed Code Resources | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PCManFM-Qt | >= 1.1.0 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 24, 2026 | CVE Modified | CVE |
| May 22, 2026 | New CVE Received | [email protected] |
Volerion