CVE-2022-25634Disclosure(qt / qt)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • qt

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Exploit: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
qt

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-17: 2Technical Details · 2026-04-17: 204-17
Signal classification2 categories
Disclosure
150.0%
Exploit
150.0%
Full discourse2 posts
  • HackenProof@HackenProof
    Disclosure

    🔍 Most pentesters stop at the password file. This researcher read the image metadata. That version number — three stages later — became CVE-2022-25634. MDVKG breaks down 5 chained vulns - CVSS 10.0 RCE in 3h 15min 🧵 https://t.co/luF1FqzbzA

    Post summary

    The post reveals that a researcher uncovered CVE‑2022‑25634 through image metadata, outlining a chain of five vulnerabilities that culminate in a CVSS 10.0 Remote Code Execution flaw.

    22034101.8K
    39.0K followersView on X
  • HackenProof@HackenProof
    Exploit

    The chain: 🔹 Metadata recon - wkhtmltopdf version 🔹 Directory traversal - admin panel discovered 🔹 SSRF - IP-based auth bypassed 🔹 shell=True - RCE confirmed 🔹 CVE-2022-25634 - library hijacking Remove any one stage. The chain breaks.

    Post summary

    The post outlines a multi‑stage exploitation chain for CVE‑2022‑25634, confirming RCE via shell=True and library hijacking, but does not provide any PoC, exploit code, or remediation advice.

    10083972
    39.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appqtqt---

Explore more