Possible QML code injection in VectorImage component
Vulnerability Description
Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-14576
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Qt Development Team
More from The Qt Company
View All →Affected Vendor
The Qt Company
View all reports →