Input validation error in konsole - CVE-2025-49091
Published: June 9, 2025
konsole
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of telnet://URL scheme. A remote attacker can trick the victim into clicking on a specially crafted URL and execute arbitrary console commands on the system with privileges of the current user.
The vulnerability affects installations without telnet client installed.
How to mitigate CVE-2025-49091
Install updates from vendor's website.
As a temporary solution you can install the telnet client, or delete the file:
/usr/share/applications/ktelnetservice6.desktop