GIMP XCF File Parsing Use-After-Free Vulnerability in GIMP Software
CVE-2025-14424

7.8HIGH

Key Information:

Vendor

Gimp

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-14424?

A use-after-free vulnerability exists in the GIMP image editor stemming from inadequate validation while parsing XCF files. This flaw enables malicious actors to execute arbitrary code remotely by enticing users to open a specially crafted XCF file or visit a malicious webpage. This vulnerability exploits the absence of proper object validation prior to operations, allowing attackers to execute code with the current process's privileges. Users are advised to stay updated with patches to mitigate potential risks.

Affected Version(s)

GIMP 3.0.6

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-14424 : GIMP XCF File Parsing Use-After-Free Vulnerability in GIMP Software