CVE-2026-48700

An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution or circumvent network namespace restrictions. NOTE: those outcomes are potentially unwanted by most users; however, the behavior of the product does comply with the applicable specification, and a simplistic solution (ensuring that the URI does not name a regular file) may have adverse consequences for I/O.
CVSS

No CVSS.

Configurations

No configuration.

History

24 May 2026, 20:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/05/24/6 -

22 May 2026, 19:21

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-22 19:17

Updated : 2026-05-24 20:16


NVD link : CVE-2026-48700

Mitre link : CVE-2026-48700

CVE.ORG link : CVE-2026-48700


JSON object : View

Products Affected

No product.

CWE
CWE-913

Improper Control of Dynamically-Managed Code Resources