CVE-2025-55014: Stardict
Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.
The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.
Affected products
- Stardict Stardict: up to and including 3.0.7+git20220909+dfsg-6
Published 2025-08-04. Last modified 2026-06-17.