CVE-2026-45184Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-05-10); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-10: 3Mentions · 2026-05-11: 1Mentions · 2026-06-16: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-10: 3Technical Details · 2026-05-11: 105-1005-1106-16
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-103
Disclosure3
2026-05-111
Patch1
2026-06-161
General1
Full discourse5 posts
  • Codean@CodeanIO
    Patch

    We looked into Kdenlive and find out that opening someone else's project was not the best idea, since it could lead to Remote Code Execution. The vulnerability (CVE-2026-45184) has been patched in version 26.04.1, make sure to update and remember: do not trust FFmpeg parameters! https://t.co/KJduYnlTKX

    Post summary

    The tweet announces that CVE-2026-45184 allows remote code execution via malicious Kdenlive projects and highlights the available patch in version 26.04.1, urging users to update. No exploitation evidence or PoC details are provided.

    1431813.7K
    416 followersView on X
  • Codean@CodeanIO
    General

    We’ve just published a blog post with the full write-up for this issue, so be sure to check it out! https://codeanlabs.com/2026/06/cve-2026-45184-popping-calc-on-kdenlive/

    Post summary

    The post announces a blog write-up on CVE-2026-45184 but provides no specific details, PoC, exploit code, patch, or claims of active exploitation.

    0221121.1K
    414 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-45184 Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used. https://www.cve.org/CVERecord?id=CVE-2026-45184 ----- Traducción: CVE-2026-45184 Kdenlive antes de 26.04.1 permite parámetros de proxy peligrosos… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-45184, a vulnerability in Kdenlive versions prior to 26.04.1 that allows malicious project files to set dangerous proxy parameters. No PoC, exploit code, or patch information is provided.

    0000021
    76 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45184 Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used. https://www.cve.org/CVERecord?id=CVE-2026-45184

    Post summary

    CVE-2026-45184 exposes a vulnerability in Kdenlive that permits dangerous proxy parameters via attacker‑controlled project files in versions before 26.04.1; no evidence of exploitation, patches, or false positive status is provided.

    00000144
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-45184 Arbitrary Proxy Parameter Injection in Kdenlive Before 26... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45184 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post summarizes the existence of CVE‑2026‑45184, noting it as an "Arbitrary Proxy Parameter Injection" in Kdenlive before version 26, and directs readers to a vulnerability details page but does not provide exploitation or mitigation details.

    0000039
    4.0K followersView on X

Explore more