KDE has issued an advisory today (October 17): https://kde.org/info/security/advisory-20201017-1.txt The issue is fixed upstream in 4.2.0, and the advisory links to commits that fixed the issue.
kpmcore-4.2.0-1.mga8 uploaded for Cauldron by David Geiger (partitionmanager is WIP).
Resolution: (none) => FIXEDStatus: NEW => RESOLVED