Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.
History

Wed, 06 May 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 05 May 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Qt
Qt qtdeclarative
CPEs cpe:2.3:a:qt:qtdeclarative:*:*:*:*:*:*:*:*
Vendors & Products Qt
Qt qtdeclarative
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 30 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Apr 2026 13:00:00 +0000

Type Values Removed Values Added
Description Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.
Title Possible QML code injection in VectorImage component
First Time appeared The Qt Company
The Qt Company qt
Weaknesses CWE-20
CWE-94
CPEs cpe:2.3:a:the_qt_company:qt:*:*:32_bit:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:64_bit:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:android:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:arm:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:ios:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:linux:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:macos:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:windows:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:x86:*:*:*:*:*
Vendors & Products The Qt Company
The Qt Company qt
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TQtC

Published: 2026-04-30T12:39:40.067Z

Updated: 2026-04-30T13:14:04.728Z

Reserved: 2025-12-12T12:52:21.516Z

Link: CVE-2025-14576

cve-icon Vulnrichment

Updated: 2026-04-30T13:13:59.958Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-30T13:16:02.850

Modified: 2026-05-05T02:57:05.760

Link: CVE-2025-14576

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-30T12:39:40Z

Links: CVE-2025-14576 - Bugzilla