AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 63 Bitcoin

Merge pull request #10972 from SomberNight/202609_qt_label_plaintext_by_default

Public commit record

What the developer wrote

Authored by ThomasV

73/100 · Adequate
Merge pull request #10972 from SomberNight/202609_qt_label_plaintext_by_default

qt/qml: labels to require opt-in to rich text
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit changes Electrum's user interface so that text labels default to plain text instead of rich text. Rich text (HTML-like formatting) can be abused if untrusted data is displayed, because it may allow attackers to inject clickable links, fake UI elements, or trigger bugs in the text-rendering engine. The patch makes rich text an opt-in choice for developers and explicitly marks trusted labels that need formatting. It also adds a runtime sanity check on Android and patches the Qt framework used in Android builds to make plain text the default at a lower level. This is a defensive hardening change rather than a fix for a specific known exploit.

Recommended action

Treat this as a security hardening patch and include it in the next release. Review any downstream forks or plugins that rely on implicit rich-text rendering in QLabel/QML labels, as they will now render as plain text unless explicitly opted in. For desktop builds, consider whether the Polish-event filter is sufficient or whether labels should be created with PlainText set before setText() is called, as noted in the code comment regarding screen readers and parser vulnerabilities.

Security signals we found

01

Default text format changed from AutoText/RichText to PlainText across Qt/QML widgets

02

New application-wide event filter forces QLabel to PlainText unless explicitly opted in

03

custom_message_box sets textFormat before setText() to prevent untrusted text from being parsed as rich text

04

Android Qt6 build patched at source level to make QQuickText default to PlainText

05

Runtime Android sanity check hard-fails if rich text is still the default

06

Plugin manifest descriptions stripped of HTML (<br/> and <a href>) to avoid rendering untrusted rich text

07

Tooltips converted from RTF/HTML to word-wrapped plain text

08

Code comment explicitly discusses risk of parser vulnerabilities and screen-reader accessibility bridge parsing HTML inside setText()

Risk score

Why this scored 63/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 10/15
Affected reach 12/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.