Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.
History

Thu, 30 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Apr 2026 13:00:00 +0000

Type Values Removed Values Added
Description Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.
Title Possible QML code injection in VectorImage component
First Time appeared The Qt Company
The Qt Company qt
Weaknesses CWE-20
CWE-94
CPEs cpe:2.3:a:the_qt_company:qt:*:*:32_bit:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:64_bit:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:android:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:arm:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:ios:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:linux:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:macos:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:windows:*:*:*:*:*
cpe:2.3:a:the_qt_company:qt:*:*:x86:*:*:*:*:*
Vendors & Products The Qt Company
The Qt Company qt
References
Metrics cvssV4_0

{'score': 7.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TQtC

Published:

Updated: 2026-04-30T13:14:04.728Z

Reserved: 2025-12-12T12:52:21.516Z

Link: CVE-2025-14576

cve-icon Vulnrichment

Updated: 2026-04-30T13:13:59.958Z

cve-icon NVD

Status : Received

Published: 2026-04-30T13:16:02.850

Modified: 2026-04-30T13:16:02.850

Link: CVE-2025-14576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.