CRITICAL🇵🇱 Wersja polska

CVE-2025-53095

CVSS 9.6v3.1pub. 2025-07-01upd. 2025-08-22

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker to craft a malicious web page that, when visited by an authenticated user, can trigger unintended actions within the Sunshine application on behalf of that user. Specifically, since the application does OS command execution by design, this issue can be exploited to abuse the "Command Preparations" feature, enabling an attacker to inject arbitrary commands that will be executed with Administrator privileges when an application is launched. This issue has been patched in version 2025.628.4510.

🤖 AI Analysis
How it works

The attacker prepares a malicious website and tricks a logged-in Sunshine user into visiting it. The victim's browser automatically sends authenticated requests to the local Sunshine web interface without the user's knowledge. Because the application is designed to execute system commands (OS command execution), the attacker can abuse the 'Command Preparations' feature by injecting arbitrary commands. These commands will be executed with administrator privileges when the user runs the application.

Impact

An attacker can execute arbitrary system commands with administrator privileges on the victim's machine, which in practice means complete takeover of the system, including data theft, malware installation, or access escalation.

Mitigation & patch

Sunshine should be updated to version 2025.628.4510 or newer, in which the issue has been fixed. Patch available in the GitHub repository (commit 738ac93a0ec1cd10412d1f339968775f53bfefe0).

Who is affected

LizardByte Sunshine — all versions prior to 2025.628.4510

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Lizardbyte Sunshine

    APP
    Lizardbyte
    < 2025.628.4510
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-32253CRITICAL9.8PL ✓same product

Auth Bypass w Lizardbyte Sunshine — obejście weryfikacji certyfikatu klienta

CVE-2025-10198HIGH7.8same product

Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing ...

CVE-2025-10199HIGH7.8same product

A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely...

CVE-2024-51738HIGH7.7same product

Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol i...

CVE-2024-31220HIGH7.3same product

Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18...