qBittorrent 5.2.4 Fixes a WebUI XSS Bug and Makes the AppImage Native on Wayland

qBittorrent 5.2.4 Fixes a WebUI XSS Bug and Makes the AppImage Native on Wayland

qBittorrent 5.2.4 was released on September 28. Most of it is polish, but one fix is security-relevant for anyone using the web interface.

The XSS fix

An XSS (cross-site scripting) vulnerability in the add-torrent window title is fixed. A crafted torrent name could inject script into the WebUI, running with your session’s permissions. Torrent names come from untrusted sources by definition, so update, especially if your WebUI is reachable from anywhere but localhost. It should not be on the public internet at all; reach it over a VPN such as WireGuard.

WebUI improvements

  • A shared dialog for adding multiple torrents at once
  • Better support for manually adding peers
  • HTTP(S) URLs from RSS articles and search results can be opened
  • Element titles set through safe properties (the change that closes the XSS class)
  • Links in torrent comments are clickable

Other fixes

  • The AppImage now runs natively on Wayland instead of through XWayland
  • Batch selection with Shift fixed, along with a column-order corruption bug in the WebUI
  • A crash in Preferences under the Italian locale
  • A crash when starting a second instance while the legal notice was showing
  • Case-only renames now work, and relative UI theme paths resolve against the config folder

What is next

A release candidate for qBittorrent 5.3 shipped alongside, with the final release expected later in 2026.

If you manage several qBittorrent instances, the new qui interface from the autobrr team is worth a look as an alternative to the built-in WebUI.

Background reading

Explainers for the concepts behind this story.