Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.9
CVE-2026-82636: Qubes OS runs commands when copying to a malicious VM
CVE-2026-82636 · published 4 days ago
Summary
In current versions of Qubes OS, copying a file from the main system (dom0) to another virtual machine can unintentionally run system commands if the target VM is controlled by an attacker. This happens because the software treats error messages like normal commands, allowing hidden code to be executed. Update Qubes OS to the latest version or apply the provided patch to stop this behavior.
What to do
- Update qubes os qubes os to version qubes-core-dom0-linux 4.3.22 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| qubes os | qubes os | < qubes-core-dom0-linux 4.3.22 |
Original advisory text
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to proc...
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metacharacters. This occurs in core-admin-linux/file-copy-vm/qfile-dom0-agent.c.
Severity
7.9
High
CVSS 3.1: 7.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published30 Aug 2026
Updated2 Sep 2026
First seen30 Aug 2026
Monitor software like this
Free during beta