CVE-2025-27142

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 25, 2025
Updated: Feb 28, 2025
CWE ID 22

Summary

CVE-2025-27142 is a vulnerability in the LocalSend app, version prior to 1.17.0. The issue lies in the lack of sanitization for paths in the `POST /api/localsend/v2/prepare-upload` and `POST /api/localsend/v2/upload` endpoints. This permits a malicious file transfer request to write files into arbitrary locations on the system, potentially enabling remote command execution. On Windows, this could be accomplished through the startup folder, while Linux may utilize Bash-related files. Users with the `Quick Save` feature enabled are particularly at risk, as files are silently written without confirmation. The vulnerability is resolved in version 1.17.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share