PT-2026-36093 · Qt Company · Qt

Published

2026-04-30

·

Updated

2026-04-30

·

CVE-2025-14576

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qt (affected versions not specified)
Description Insufficient validation of node IDs in the Qt SVG module enables arbitrary QML/JavaScript code injection. This occurs when the VectorImage component in Qt Quick loads malicious SVG files. Such injection can lead to denial of service, information disclosure, or other impacts, depending on the application's privilege level and data access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Code Injection

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-14576
RHSA-2026:7620
RHSA-2026:7846

Affected Products

Qt