CVE-2025-55014: Stardict

Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.

Affected products

  • Stardict Stardict: up to and including 3.0.7+git20220909+dfsg-6

Published 2025-08-04. Last modified 2026-06-17.