{"id":"CVE-2025-13947","title":"A flaw was found in WebKitGTK","summary":"A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify tha…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N","cwe":["CWE-346"],"published":"2025-12-03","updated":"2026-06-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-13947","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:22789","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:22790","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:23110","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:23433","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:23434","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:23451","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:23452","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:23583","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:23591","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:23742","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:23743","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-13947","label":"secalert@redhat.com"},{"url":"https://bugs.webkit.org/show_bug.cgi?id=271957","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2418576","label":"secalert@redhat.com"}],"tags":["nvd","exploit-available"],"epss":0.00331,"epssPercentile":0.26503,"ingestedAt":"2026-06-29T13:24:34.614Z","exploits":{"github":1,"githubRepos":["https://github.com/sirredbeard/WebKitGTK-DND-Fix"],"checkedAt":"2026-09-24T07:52:52.923Z"},"exploitAvailable":true,"slug":"CVE-2025-13947","body":"## Overview\n\nA flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal any file the user is permitted to read via abusing the file drag-and-drop mechanism where WebKitGTK does not verify that drag operations originate from outside the browser.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":40.7,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":4788,"id":"CVE-2025-13947","ts":1788887206244,"field":"exploit_available","old":"false","new":"true"},{"seq":3671,"id":"CVE-2025-13947","ts":1788886323102,"field":"exploit_available","old":"true","new":"false"},{"seq":2522,"id":"CVE-2025-13947","ts":1788882991572,"field":"exploit_available","old":"false","new":"true"},{"seq":1551,"id":"CVE-2025-13947","ts":1788882404503,"field":"exploit_available","old":"true","new":"false"},{"seq":665,"id":"CVE-2025-13947","ts":1788881842238,"field":"exploit_available","old":"false","new":"true"}]}