← All Advisories

Qt SVG VectorImage Skips Node ID Validation, Allowing Code Injection When an Application Renders a Crafted SVG File

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2025-14576

Key Details

CVECVE-2025-14576
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Hardened Images, qt qtdeclarative, and qt Qt
Classified asCWE-20 (Improper Input Validation)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
Red HatRed Hat Hardened Images
qtqtdeclarative
qtQt
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access. (NVD)

What to Do

Monitor Red Hat's and qt's web pages for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-14576
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-14576