Executive brief
KDE Dolphin, a popular file manager for Linux systems, contains a vulnerability that allows sandboxed applications (like those in Flatpak or AppArmor) to bypass security restrictions. By exploiting how Dolphin handles folder-opening requests, a malicious application can trick the system into running unauthorized scripts or executables outside of its restricted environment. This could lead to a full system compromise or unauthorized access to sensitive user data.
Technical details
A vulnerability in Dolphin's implementation of the org.freedesktop.FileManager1.ShowFolders D-Bus interface allows for a sandbox escape. While the protocol is intended to only handle folder paths, Dolphin incorrectly processed file paths, including executables and scripts, as valid arguments. If an attacker provides a path to a malicious executable, Dolphin may attempt to 'activate' or run the file. While Dolphin typically prompts the user before execution, this behavior bypasses the intended security boundary of Flatpak or AppArmor confinement, potentially leading to arbitrary code execution if the user accepts the prompt or has configured Dolphin to run scripts automatically. The issue is fixed in version 25.12.3.
Affected products
- KDE Dolphin before 25.12.3
Timeline
- 2026-04-27: advisory: KDE Project Security Advisory released
- 2026-04-28: disclosed: CVE-2026-41525 published
- 2026-05-05: patched: Version 25.12.3 released with fix