Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access. | |
| Title | Possible QML code injection in VectorImage component | |
| First Time appeared |
The Qt Company
The Qt Company qt |
|
| Weaknesses | CWE-20 CWE-94 |
|
| CPEs | cpe:2.3:a:the_qt_company:qt:*:*:32_bit:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:64_bit:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:android:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:arm:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:ios:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:linux:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:macos:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:windows:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:x86:*:*:*:*:* |
|
| Vendors & Products |
The Qt Company
The Qt Company qt |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TQtC
Published:
Updated: 2026-04-30T13:14:04.728Z
Reserved: 2025-12-12T12:52:21.516Z
Link: CVE-2025-14576
Updated: 2026-04-30T13:13:59.958Z
Status : Received
Published: 2026-04-30T13:16:02.850
Modified: 2026-04-30T13:16:02.850
Link: CVE-2025-14576
No data.
OpenCVE Enrichment
No data.