CVE-2025-14576
Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.
Published:Apr 30, 2026
Last Modified:Jul 29, 2026
EPS:Apr 30, 2026
EPSS Score:0.00224
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Qt
Product
Qt
Qt
Qt
Vendor
Qt
Product
Qtdeclarative
Qt
Qtdeclarative
Vendor
The Qt Company
Product
Qt
The Qt Company
Qt
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
