Vulnerability Description
qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qbittorrent | Qbittorrent | < 5.1.2 |
Related Weaknesses (CWE)
References
- https://github.com/qbittorrent/qBittorrent/commit/6ad073e0bc26c1f9d3530490ece611Patch
- https://github.com/qbittorrent/qBittorrent/commit/ad68813fe879ba245a4f41f105ed8dPatch
- https://www.qbittorrent.org/news#wed-jul-02nd-2025---qbittorrent-v5.1.2-releaseRelease Notes
FAQ
What is CVE-2025-54310?
CVE-2025-54310 is a vulnerability with a CVSS score of 4.0 (MEDIUM). qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.
How severe is CVE-2025-54310?
CVE-2025-54310 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-54310?
Check the references section above for vendor advisories and patch information. Affected products include: Qbittorrent Qbittorrent.