---
id: CVE-2020-24742
title: >-
  An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to
  load plugins relative to the working directory, allowing attackers to execute
  arbitrary code via crafted files.
summary: >-
  An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to
  load plugins relative to the working directory, allowing attackers to execute
  arbitrary code via crafted files.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
vendor: qt
product: qt
affected:
  - 'qt >= 5.6.0, < 5.12.7'
  - 'qt >= 5.13.0, <= 5.13.2'
patched:
  - qt 5.12.7
published: '2021-08-09'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:26.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-24742'
references:
  - url: 'https://codereview.qt-project.org/c/qt/qtbase/+/280730'
    label: cve@mitre.org
  - url: 'https://codereview.qt-project.org/c/qt/qtbase/+/280730'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01167
epssPercentile: 0.66363
ingestedAt: '2026-10-08T22:11:53.740Z'
---

## Overview

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

## Affected

- `qt >= 5.6.0, < 5.12.7`
- `qt >= 5.13.0, <= 5.13.2`

## Remediation

Upgrade past the affected range:

- `qt 5.12.7`
