CVE-2022-25255Uncontrolled Search Path Element in QT

Severity
7.8HIGHNVD
OSV7.5
EPSS
0.1%
top 76.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 16
Latest updateMar 5

Description

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages8 packages

NVDqt/qt5.9.05.15.9+1
debiandebian/qt6-base< qt6-base 6.2.4+dfsg-4 (bookworm)
debiandebian/qtbase-opensource-src< qt6-base 6.2.4+dfsg-4 (bookworm)
debiandebian/qtbase-opensource-src-gles< qt6-base 6.2.4+dfsg-4 (bookworm)

Patches

🔴Vulnerability Details

3
OSV
qtbase-opensource-src vulnerabilities2026-03-05
GHSA
GHSA-fw78-qp2x-5gc7: In Qt 52022-02-17
OSV
CVE-2022-25255: In Qt 52022-02-16

📋Vendor Advisories

4
Ubuntu
Qt vulnerabilities2026-03-05
Red Hat
qt: QProcess could execute a binary from the current working directory when not found in the PATH2022-02-16
Microsoft
In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX QProcess could execute a binary from the current working directory when not found in the PATH.2022-02-08
Debian
CVE-2022-25255: qt6-base - In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX,...2022
CVE-2022-25255 — Uncontrolled Search Path Element in QT | cvebase