PatchSiren

LXQt CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL LXQt CVE published 2026-05-22

CVE-2026-48700

A critical vulnerability was discovered in PCManFM-Qt, a file manager application, that allows for code execution when a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call. This issue, tracked as CVE-2026-48700, has a CVSS score of 9.3 and is considered critical. The vulnerability exists due to the application's handling of file paths, which could be ex [truncated]