Junglewise Threat Intelligence

CVE-2025-14576: The Qt Company Qt SVG code injection in VectorImage component

CVE-2025-14576 · Severity: high · CVSS 7.8 · Published 2026-04-30

Technologies: Red Hat Enterprise Linux 10. Vendors: The Qt Company, Red Hat.

Executive brief

A vulnerability in the Qt software framework could allow an attacker to execute malicious code when a user opens a specially crafted SVG image file. Qt is a widely used library for building graphical user interfaces across desktop, mobile, and embedded systems. If exploited, this flaw could allow an attacker to steal sensitive information, disrupt application services, or gain unauthorized access to data depending on the application's permissions.

Technical details

A code injection vulnerability exists in the Qt SVG module due to improper input validation of node IDs. When a malicious SVG file is processed via the VectorImage component in Qt Quick, an attacker can inject and execute arbitrary QML or JavaScript code. The attack requires a user to open or load a specially crafted SVG file (User Interaction). While QML execution environments are often sandboxed or restricted compared to native code, successful exploitation can lead to full compromise of the application's data and functionality, including denial of service and information disclosure. Patches have been developed for the qtdeclarative component to address this validation failure.

Affected products

  • The Qt Company Qt SVG module Qt 6.x versions prior to patch 697273
  • Red Hat Red Hat Enterprise Linux 10 10.0, 10.2

Timeline

  • 2026-04-30: disclosed: Initial publication date
  • 2026-05-26: patched: Red Hat released security updates for RHEL 10 (RHSA-2026:20567)

References