Back Linuxsecurity Ubuntu 26.04 Kdenlive Important Command Execution Risk USN-8856
Running self-managed GitLab? Critical flaws could allow server code execution. Check the fixes. ×
Kdenlive, MLT could be made to run programs as your login if it opened a specially crafted file. Software Description: - kdenlive: KDE Non-Linear Video Editor - mlt: Multimedia Framework Details: It was discovered that Kdenlive allowed dangerous proxy parameters when processing attacker-controlled project files. An attacker could use this to execute arbitrary commands via the MLT framework's ante/post consumer properties.
Kdenlive, MLT could be made to run programs as your login if it opened a
specially crafted file.
Software Description:
- kdenlive: KDE Non-Linear Video Editor
- mlt: Multimedia Framework
It was discovered that Kdenlive allowed dangerous proxy parameters when
processing attacker-controlled project files. An attacker could use this to
execute arbitrary commands via the MLT framework's ante/post consumer
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS kdenlive 4:25.12.3-0ubuntu1.1 libmlt7 7.36.1-1ubuntu3.1 melt 7.36.1-1ubuntu3.1 In general, a standard system update will make all the necessary changes.
Ubuntu Security Notice USN-8856-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
