Cross-site Scripting (XSS) Affecting qt6-qtwebengine package, versions <6.9.3-r2


Severity

Recommended
0.0
critical
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.51% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ALPINE324-QT6QTWEBENGINE-17303498
  • published11 Jun 2026
  • disclosed7 Feb 2025

Introduced: 7 Feb 2025

CVE-2025-24028  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade Alpine:3.24 qt6-qtwebengine to version 6.9.3-r2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream qt6-qtwebengine package and not the qt6-qtwebengine package as distributed by Alpine. See How to fix? for Alpine:3.24 relevant fixed versions and status.

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences between how Joplin's HTML sanitizer handles comments and how the browser handles comments. This affects both the Rich Text Editor and the Markdown viewer. However, unlike the Rich Text Editor, the Markdown viewer is cross-origin isolated, which prevents JavaScript from directly accessing functions/variables in the toplevel Joplin window. This issue is not present in Joplin 3.1.24 and may have been introduced in 9b50539. This is an XSS vulnerability that impacts users that open untrusted notes in the Rich Text Editor. This vulnerability has been addressed in version 3.2.12 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS Base Scores

version 3.1