CVE-2025-13947
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-03

Last updated on: 2026-04-20

Assigner: Red Hat, Inc.

Description
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-03
Last Modified
2026-04-20
Generated
2026-06-16
AI Q&A
2025-12-03
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
redhat enterprise_linux 9
redhat enterprise_linux 8
webkitgtk webkitgtk *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability in WebKitGTK allows a remote attacker to trick a user into dragging and dropping files from their local system via a malicious webpage. Because WebKitGTK does not properly verify if drag operations originate from outside the browser, the attacker can gain access to any files the user is permitted to read, leading to unintended information disclosure. [1]

Impact Analysis

If exploited, this vulnerability can expose sensitive local files to a remote attacker when the user interacts with a malicious webpage. This can lead to unauthorized disclosure of personal or confidential information stored on the user's system. [1]

Mitigation Strategies

To mitigate this vulnerability, you should update WebKitGTK to a version where this flaw is fixed. Avoid interacting with untrusted websites that may exploit the drag-and-drop mechanism. Additionally, consider restricting or monitoring drag-and-drop operations in browsers using WebKitGTK until a patch is applied. [1]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-13947. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart