CVE-2025-14576

Source
https://cve.org/CVERecord?id=CVE-2025-14576
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14576.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-14576
Downstream
Published
2026-04-30T13:16:02.850Z
Modified
2026-07-31T03:33:47.072941833Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

Database specific
{
    "unresolved_ranges": [
        {
            "vendor_product": "qt:qtdeclarative",
            "cpes": [
                "cpe:2.3:a:qt:qtdeclarative:*:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "6.8.0"
                },
                {
                    "fixed": "6.8.6"
                }
            ],
            "source": "CPE_RANGE"
        }
    ]
}
References

Affected packages

Git / github.com/qt/qtdeclarative

Affected ranges

Type
GIT
Repo
https://github.com/qt/qtdeclarative
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:qt:qtdeclarative:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "6.10.0"
        },
        {
            "fixed": "6.10.1"
        }
    ],
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14576.json"