CVE Vulnerabilities

CVE-2025-13947

Origin Validation Error

Published: Dec 03, 2025 | Modified: Jan 07, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.4 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatwebkitgtk4-0:2.50.3-2.el7_9*
Red Hat Enterprise Linux 8RedHatwebkit2gtk3-0:2.50.3-1.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatwebkit2gtk3-0:2.50.3-2.el8_2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatwebkit2gtk3-0:2.50.3-2.el8_4*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatwebkit2gtk3-0:2.50.3-2.el8_4*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatwebkit2gtk3-0:2.50.3-2.el8_6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatwebkit2gtk3-0:2.50.3-2.el8_6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatwebkit2gtk3-0:2.50.3-2.el8_6*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatwebkit2gtk3-0:2.50.3-2.el8_8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatwebkit2gtk3-0:2.50.3-2.el8_8*
Red Hat Enterprise Linux 9RedHatwebkit2gtk3-0:2.50.3-1.el9_7*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatwebkit2gtk3-0:2.50.3-1.el9_0*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatwebkit2gtk3-0:2.50.3-1.el9_2*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatwebkit2gtk3-0:2.50.3-1.el9_4*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatwebkit2gtk3-0:2.50.3-1.el9_6*
Qtwebkit-opensource-srcUbuntuesm-apps/bionic*
Qtwebkit-opensource-srcUbuntuesm-apps/focal*
Qtwebkit-opensource-srcUbuntuesm-apps/jammy*
Qtwebkit-opensource-srcUbuntuesm-apps/noble*
Qtwebkit-opensource-srcUbuntuesm-infra/xenial*
Qtwebkit-opensource-srcUbuntujammy*
Qtwebkit-opensource-srcUbuntunoble*
Qtwebkit-sourceUbuntuesm-apps/bionic*
Qtwebkit-sourceUbuntuesm-apps/xenial*
Webkit2gtkUbuntudevel*
Webkit2gtkUbuntuesm-infra/bionic*
Webkit2gtkUbuntuesm-infra/focal*
Webkit2gtkUbuntuesm-infra/xenial*
Webkit2gtkUbuntujammy*
Webkit2gtkUbuntunoble*
Webkit2gtkUbuntuplucky*
Webkit2gtkUbuntuquesting*
Webkit2gtkUbuntuupstream*
WebkitgtkUbuntuesm-apps/bionic*
WebkitgtkUbuntuesm-apps/xenial*
WpewebkitUbuntuesm-apps/focal*
WpewebkitUbuntuesm-apps/jammy*
WpewebkitUbuntujammy*
WpewebkitUbuntuupstream*

References