Skip to content
Ubuntu 26.04 Kdenlive Important Command Execution Risk USN-8856

Ubuntu 26.04 Kdenlive Important Command Execution Risk USN-8856

Linuxsecurity •LinuxSecurity Advisories • September 30, 2026

Running self-managed GitLab? Critical flaws could allow server code execution. Check the fixes. ×

Kdenlive, MLT could be made to run programs as your login if it opened a specially crafted file. Software Description: - kdenlive: KDE Non-Linear Video Editor - mlt: Multimedia Framework Details: It was discovered that Kdenlive allowed dangerous proxy parameters when processing attacker-controlled project files. An attacker could use this to execute arbitrary commands via the MLT framework's ante/post consumer properties.

Kdenlive, MLT could be made to run programs as your login if it opened a

specially crafted file.

Software Description:

- kdenlive: KDE Non-Linear Video Editor

- mlt: Multimedia Framework

It was discovered that Kdenlive allowed dangerous proxy parameters when

processing attacker-controlled project files. An attacker could use this to

execute arbitrary commands via the MLT framework's ante/post consumer

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS kdenlive 4:25.12.3-0ubuntu1.1 libmlt7 7.36.1-1ubuntu3.1 melt 7.36.1-1ubuntu3.1 In general, a standard system update will make all the necessary changes.

Ubuntu Security Notice USN-8856-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Companies (1)

CWE Weaknesses (1)

Platforms (2)