PatchSiren cyber security CVE debrief
CVE-2026-45184 Commits CVE debrief
CVE-2026-45184 is a medium-severity issue in Kdenlive where opening an attacker-controlled project file can lead to dangerous proxy parameters being used before version 26.04.1. The main risk is tied to untrusted project files and user interaction, so teams should treat imported or shared Kdenlive projects as potentially unsafe until the fixed release is in place.
- Vendor
- Commits
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-09
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-05-09
- Advisory updated
- 2026-07-20
Who should care
Kdenlive users, video editors, and workstation administrators who open project files from outside their organization should pay attention. This is especially relevant in environments where project files are exchanged by email, chat, shared storage, or ticketing systems.
Technical summary
According to the NVD description and linked KDE references, Kdenlive before 26.04.1 accepts proxy-related parameters from an attacker-controlled project file in a way that can be dangerous. The published CVSS vector (AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L) indicates the issue requires user interaction and can affect confidentiality and integrity significantly, with some availability impact. The listed weakness is CWE-829, which aligns with unsafe handling of externally influenced data or control values.
Defensive priority
Medium. Prioritize if your users regularly open third-party Kdenlive projects or if editors work with files from untrusted sources. Update to the fixed release promptly, but this is not currently marked as KEV or ransomware-linked in the provided corpus.
Recommended defensive actions
- Upgrade Kdenlive to 26.04.1 or later.
- Treat shared or downloaded Kdenlive project files as untrusted input.
- Review workflows that auto-open or routinely import project files from external sources.
- If you cannot upgrade immediately, restrict opening of untrusted project files to trusted workstations and users.
- Monitor vendor advisories and package updates for KDE/Kdenlive security fixes.
Evidence notes
This debrief is based only on the supplied CVE record metadata: the NVD description, CVSS vector, CWE-829 classification, and the referenced KDE advisory and Kdenlive commit links. The vendor field in the source corpus is low-confidence and marked for review, so claims are kept limited to the explicit CVE description and metadata.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45184 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45184
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45184 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45184
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://commits.kde.org/kdenlive/94042ddd259551e4a7a5f6672329752972c84685
-
Source reference
Unverified legacy reference
URL: https://commits.kde.org/kdenlive/c3999aacc6da54756f3df8aab03b900459562ecd
-
Source reference
Unverified legacy reference
URL: https://kde.org/info/security/advisory-20260508-1.txt
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.