CVE-2025-13947

A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
Configurations

No configuration.

History

No history.

Information

Published : 2025-12-03 10:15

Updated : 2026-01-07 16:15


NVD link : CVE-2025-13947

Mitre link : CVE-2025-13947

CVE.ORG link : CVE-2025-13947


JSON object : View

Products Affected

No product.

CWE
CWE-346

Origin Validation Error