External risk intelligence

Meltytech Shotcut Buffer Overflow via Manipulated MLT Project Files

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-65834

Shotcut is a desktop video editing application. It is a client-side tool intended for local use by individual users. It does not function as a network service, public API, or internet-facing gateway, and it is not designed to accept untrusted network connections in typical deployments.

Buffer Overflow

Meltytech Shotcut

25.10.31

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability found in Meltytech Shotcut software that allows for a buffer overflow when processing specially crafted project files. While the software is primarily a local desktop application, the potential for code execution or denial of service warrants attention to confirm its presence and impact within your environment. The main concern is confirming relevance and exposure.

  • A software flaw allows malicious files to crash or control the application.
  • It's critical to know if this video editing tool is used locally.
  • Confirm if the affected software is present and its usage.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by tricking a user into opening a specially crafted MLT project file. When the application attempts to process this malicious file, it encounters an error due to excessively large width and height parameters, leading to a buffer overflow. This flaw can result in a complete compromise of the application's integrity and the user's system.

  • No user interaction required.
  • Malicious project file opens.
  • Potential for full system compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to cause a denial-of-service condition or potentially execute arbitrary code when a user opens a specially crafted MLT project file in Shotcut. The issue stems from the application's handling of extremely large width and height parameters in project files, leading to an attempt to allocate excessive memory.

  • Application stability and integrity.
  • Opening a manipulated project file.
  • Application crash or potential code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects the Meltytech Shotcut video editing software. Responsibility for addressing this issue likely falls to end-users or IT teams managing individual workstations where Shotcut is installed, given its nature as a desktop application. The first practical step is to identify users with Shotcut installed, confirm their specific version, and assess the business criticality of their usage to prioritize remediation efforts, which may involve vendor coordination or user guidance.

  • Ownership: Individual users and workstation IT teams.
  • Verify first: Confirm Shotcut installation and version.
  • Action: Guide users to update or reinstall.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Meltytech Shotcut?

Shotcut is a free, open-source video editing application used to create and manipulate multimedia content. It allows creators to perform complex tasks like timeline editing and color grading on their local workstations. Because it processes various media formats and project files, the software must carefully manage system memory to handle video dimensions and resolution settings correctly.

What does CWE-120 mean for CVE-2025-65834?

CWE-120 refers to a classic Buffer Overflow weakness. In this vulnerability, the software fails to properly check the size of input data—specifically the width and height values within an MLT project file. When these numbers are intentionally made massive, the program tries to allocate more memory than it can safely handle, which can corrupt program execution and potentially allow unauthorized code to run.

How is this vulnerability triggered?

An attacker triggers the flaw by creating a malicious MLT project file with manipulated, extreme dimension parameters. The bug is triggered when a user opens this specific file in the affected version of Shotcut. It is important to note that standard, properly formatted project files created during normal editing workflows do not trigger this memory access violation.

Do I need to worry about this if Shotcut is only used locally?

Yes, but your risk profile is different. According to Halo Surface Signal, Shotcut is a desktop tool and not a network-facing service or server. While it is not internet-facing, the risk remains if a user is tricked into opening an untrusted project file from an external source, such as a download or an email attachment, which would execute the malicious code on their local system.

Why should I check my systems for Shotcut?

You should check for Shotcut to determine if any workstations in your environment are running version 25.10.31. Since this is a client-side application, responsibility for mitigation lies with the users or IT teams managing those specific computers. Identifying where the software exists is the first step toward coordinating updates or providing guidance to users on avoiding untrusted project files.

References