CVE-2025-27142
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-27142 is a vulnerability in the LocalSend app, version prior to 1.17.0. The issue lies in the lack of sanitization for paths in the `POST /api/localsend/v2/prepare-upload` and `POST /api/localsend/v2/upload` endpoints. This permits a malicious file transfer request to write files into arbitrary locations on the system, potentially enabling remote command execution. On Windows, this could be accomplished through the startup folder, while Linux may utilize Bash-related files. Users with the `Quick Save` feature enabled are particularly at risk, as files are silently written without confirmation. The vulnerability is resolved in version 1.17.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.