> USN-8856-1: Kdenlive, MLT vulnerability
[DATE: 30/09/2026 15:59]
[LANGUAGE: EN]
It was discovered that Kdenlive allowed dangerous proxy parameters when
processing attacker-controlled project files. An attacker could use this to
execute arbitrary commands via the MLT framework's ante/post consumer
properties.