CVE-2025-54310

qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.
Configurations

Configuration 1 (hide)

cpe:2.3:a:qbittorrent:qbittorrent:*:*:*:*:*:*:*:*

History

09 Oct 2025, 16:31

Type Values Removed Values Added
References () https://github.com/qbittorrent/qBittorrent/commit/6ad073e0bc26c1f9d3530490ece611b49f5bfcab - () https://github.com/qbittorrent/qBittorrent/commit/6ad073e0bc26c1f9d3530490ece611b49f5bfcab - Patch
References () https://github.com/qbittorrent/qBittorrent/commit/ad68813fe879ba245a4f41f105ed8d2114a92971 - () https://github.com/qbittorrent/qBittorrent/commit/ad68813fe879ba245a4f41f105ed8d2114a92971 - Patch
References () https://www.qbittorrent.org/news#wed-jul-02nd-2025---qbittorrent-v5.1.2-release - () https://www.qbittorrent.org/news#wed-jul-02nd-2025---qbittorrent-v5.1.2-release - Release Notes
First Time Qbittorrent qbittorrent
Qbittorrent
CPE cpe:2.3:a:qbittorrent:qbittorrent:*:*:*:*:*:*:*:*

22 Jul 2025, 13:06

Type Values Removed Values Added
Summary
  • (es) Las versiones anteriores a qBittorrent 5.1.2 no impiden el acceso a un archivo local referenciado en la URL de un enlace. Esto afecta a rsswidget.cpp y searchjobwidget.cpp.

18 Jul 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-18 20:15

Updated : 2025-10-09 16:31


NVD link : CVE-2025-54310

Mitre link : CVE-2025-54310

CVE.ORG link : CVE-2025-54310


JSON object : View

Products Affected

qbittorrent

  • qbittorrent
CWE
CWE-669

Incorrect Resource Transfer Between Spheres