目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-53964 PoC — goldendict 安全漏洞

来源
关联漏洞
标题: goldendict 安全漏洞 (CVE-2025-53964)
Description:goldendict是goldendict开源的一个功能丰富的词典查找程序。 goldendict 1.5.0和1.5.1版本存在安全漏洞,该漏洞源于暴露危险方法,可能导致文件读取和修改。
介绍
# CVE-2025-53964
## Risk assessment
CVSS v3: (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L) - 9.6/10
## Description
GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds
a crafted dictionary and then searches for any term included in that dictionary.
## Additional Information
The product provides interface for interaction with external actors, which includes a dangerous method in GoldenDict (ver. 1.5.0, 1.5.1) that is not properly restricted. This allows remote attacker get access to read and modify files on the user file system when a prepared malicious dictionary is added and used in the program.
## Vulnerability type
CWE-749: Exposed Dangerous Method or Function; CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
## Vendor of Product
GoldenDict Project
## Affected Product Code Base
GoldenDict - 1.5.0, 1.5.1
## Affected Component
GoldenDict executable, source code file xdxf.cc, source code file xdxf2html.cc, source code file stardict.cc.
## Attack Type
Remote
## Impact Code execution
true
## Impact Information Disclosure
true
## CVE Impact Other
Access to read and modify files on the user file system
## Attack Vectors
To exploit the vulnerability, a user must add a malicious dictionary to the program and search for any term included in that dictionary.
## Discoverer
Grebennikov Timofey, a specialist in the penetration testing group of the security control department of the development of the Astra Group.
## Reference
https://github.com/goldendict/goldendict/releases
## Details
GoldenDict is a graphical program for searching terms in Wikipedia and locally installed dictionaries. Various dictionary formats are supported, including the XDXF format with XML markup. Dictionaries are distributed on the Internet by other users.

The program uses a browser engine, which is included in the Qt Widgets components package, to render and display words from dictionaries.

Several security violations were discovered at once, which allow the implementation of a critical vulnerability:
1) Lack of sanitization of XML content;
2) Lack of prohibition on execution of JS code;
3) Disabled or weak CSP policy.

Together, these violations lead to the possibility of gaining access to user files by embedding malicious JS code in the XML markup of an XDXF dictionary downloaded from the Internet.
## Proof-of-Concept
PoC will be added to this page within 90 days of the vulnerability being published, or sooner if an official patch is published by the vendor.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →