We have published Qubes Security Bulletin (QSB) 118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting . The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions. Qubes Security Bulletin 118 ---===[ Qubes Security Bulletin 118 ]===--- 2026-08-28 Dom0 arbitrary code execution in qvm-copy-to-vm error reporting User action ------------ Continue to update normally [1] in order to receive the security updates described in the "Patching" section below. No other user action is required in response to this QSB. Summary -------- If `qvm-copy-to-vm` is used to copy a file from dom0 to a malicious qube, that qube can inject an arbitrary command into dom0.…