VYPR

Qt Quick

by Qt

CVEs (1)

  • CVE-2025-14576HigApr 30, 2026
    risk 0.44cvss 7.8epss 0.00

    Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead…