File: //bin/cautious-launcher
#!/bin/bash
# For use with .desktop files and MIME handlers so that the Ubuntu Policy
# can be followed: programs cannot be executed when they lack the execute bit.
# https://wiki.ubuntu.com/SecurityTeam/Policies#Execute-Permission%20Bit%20Required
#
# This was updated to fix CVE-2026-10037 and prevent application confinement escape
exe="$1"
shift || true
if [ -n "$exe" ] && \
[ "${exe:0:5}" != "/usr/" ] && [ "${exe:0:5}" != "/opt/" ]
then
if [ -n "$DISPLAY" ] && [ -x /usr/bin/zenity ]; then
/usr/bin/zenity --error --title "Blocked: $*" --text "For security reasons, running the file '$exe' has been blocked."
else
echo "$*: '$exe' has been blocked for security reasons. Aborting." >&2
fi
exit 1
fi
exec "$@" "$exe"