A security notice published on October 1, 2026 reports that incorrect argument quoting in KShell::quoteArgs could allow shell escape and arbitrary command execution.
Notice USN-8857-1, published on October 1, 2026, says KCoreAddons incorrectly handled shell argument quoting in the KShell::quoteArgs function. According to the report, inadequate handling of shell metacharacters could allow an escape from the shell.
Applications that relied on this method to handle user input could, under certain conditions, allow an attacker to execute arbitrary commands. The text consulted is an automatic translation of the Ubuntu security feed. To confirm the details and any remediation guidance, consult the original USN-8857-1 notice through official Ubuntu Security channels.