An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution or circumvent network namespace restrictions. NOTE: those outcomes are potentially unwanted by most users; however, the behavior of the product does comply with the applicable specification, and a simplistic solution (ensuring that the URI does not name a regular file) may have adverse consequences for I/O.
CVSS
No CVSS.
References
Configurations
No configuration.
History
24 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
22 May 2026, 19:21
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-22 19:17
Updated : 2026-05-24 20:16
NVD link : CVE-2026-48700
Mitre link : CVE-2026-48700
CVE.ORG link : CVE-2026-48700
JSON object : View
Products Affected
No product.
CWE
CWE-913
Improper Control of Dynamically-Managed Code Resources
