OS Command Injection Vulnerability in Qubes OS by Qubes Inc.
CVE-2026-82636
7.9HIGH
What is CVE-2026-82636?
An OS command injection vulnerability has been identified in Qubes OS prior to version 4.3.22. The issue arises during the qvm-copy-to-vm call from dom0 to a maliciously-controlled qube. The underlying cause is the improper handling of error messages by the 'system' library, which may permit the inclusion of shell metacharacters. This flaw could potentially be exploited by an attacker to execute arbitrary commands within the host system, compromising the security model of the OS.
Affected Version(s)
Qubes OS 0
