CRITICAL🇵🇱 Wersja polska

CVE-2025-54792

CVSS 9.3v4.0pub. 2025-08-01upd. 2025-09-03

LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without needing an internet connection. In versions 1.16.1 and below, a critical Man-in-the-Middle (MitM) vulnerability in the software's discovery protocol allows an unauthenticated attacker on the same local network to impersonate legitimate devices, silently intercepting, reading, and modifying any file transfer. This can be used to steal sensitive data or inject malware, like ransomware, into files shared between trusted users. The attack is hardly detectable and easy to implement, posing a severe and immediate security risk. This issue was fixed in version 1.17.0.

🤖 AI Analysis
How it works

The vulnerability results from lack of proper device identity verification (CWE-345) and the possibility of intercepting communication in the device discovery channel (CWE-300). An attacker present on the same local network can advertise themselves as a legitimate LocalSend device, persuading victims to establish a connection with them instead of the intended recipient. The attack is difficult to detect by the user and simple to implement.

Impact

An attacker can silently intercept, read, and modify any files transmitted between LocalSend application users, which may lead to theft of sensitive data or injection of malicious software (e.g., ransomware) into transferred files.

Mitigation & patch

Update the LocalSend application to version 1.17.0 or later, where the issue has been fixed. The patch is available in the official project repository on GitHub (tag v1.17.0).

Who is affected

LocalSend in versions 1.16.1 and earlier

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Localsend

    APP
    Localsend
    < 1.17.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-25154MEDIUM6.1same product

LocalSend to darmowa aplikacja open-source umożliwiająca użytkownikom udostępnianie plików i wiadomości urządz...

CVE-2025-27142MEDIUM6.3same product

LocalSend is a free, open-source app that allows users to securely share files and messages with nearby device...