CVE-2025-53095

Source
https://cve.org/CVERecord?id=CVE-2025-53095
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53095.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-53095
Aliases
  • GHSA-39hj-fxvw-758m
Published
2025-07-01T01:33:22Z
Modified
2026-08-12T15:13:59Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Sunshine application-wide CSRF in the UI leads to command injection as Administrator
Details

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker to craft a malicious web page that, when visited by an authenticated user, can trigger unintended actions within the Sunshine application on behalf of that user. Specifically, since the application does OS command execution by design, this issue can be exploited to abuse the "Command Preparations" feature, enabling an attacker to inject arbitrary commands that will be executed with Administrator privileges when an application is launched. This issue has been patched in version 2025.628.4510.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-352"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53095.json"
}
References

Affected packages

Git / github.com/lizardbyte/sunshine

Affected ranges

Type
GIT
Repo
https://github.com/lizardbyte/sunshine
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:lizardbyte:sunshine:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2025.628.4510"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.1
v0.10.0
v0.11.0
v0.11.1
v0.2.0
v0.3.0
v0.3.1
v0.4.0
v0.8.0
v0.9.0
v2025.*
v2025.118.151840
v2025.122.141614

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53095.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "111895245452397865931689791366140668605",
            "length": 1217
        },
        "id": "CVE-2025-53095-4e552219",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/738ac93a0ec1cd10412d1f339968775f53bfefe0",
        "target": {
            "file": "src/confighttp.cpp",
            "function": "uploadCover"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "212956361864509626197879692058320906524",
                "184840781174164536877521092334400672444",
                "283106148898810440707172633955193446049",
                "268925405016830700229153979821007473362",
                "255616432110605973807457280840205954922",
                "203215498917427026273234561746737700266",
                "240605006573948468832353187021843097117",
                "213073478700809629252658669702218518016"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-53095-6ba58442",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/65f14e1003f831e776c170621bd06d8292f65155",
        "target": {
            "file": "src/config.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "217155913941110091307055735056887614458",
            "length": 781
        },
        "id": "CVE-2025-53095-78f5d15b",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/738ac93a0ec1cd10412d1f339968775f53bfefe0",
        "target": {
            "file": "src/confighttp.cpp",
            "function": "saveConfig"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "41224223134574435452519175642988263752",
            "length": 214
        },
        "id": "CVE-2025-53095-92fcb3bf",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/738ac93a0ec1cd10412d1f339968775f53bfefe0",
        "target": {
            "file": "src/confighttp.cpp",
            "function": "closeApp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "222037659870719001303497657898388770442",
            "length": 1254
        },
        "id": "CVE-2025-53095-9729e2c7",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/738ac93a0ec1cd10412d1f339968775f53bfefe0",
        "target": {
            "file": "src/confighttp.cpp",
            "function": "deleteApp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "161193495897928634847744687348253111883",
                "240807361837974290428751974259132268775",
                "8991807846442357860322564687000710317",
                "138639410016757863907133810891017338003",
                "334178669102994877414585853014755265225",
                "156866017668790458963950660841290791235",
                "27445238177274725376662396584638982944",
                "307695949424423144432619553625454384055",
                "310189885014406386023403870026366850802",
                "92460686124000986525404620434611298230",
                "23524259528603066898818020321228951823",
                "260015299602924734755742727500447028547",
                "256643191707759184497011914690053314386",
                "204228639474991941204882078676044403762",
                "178584978428589738109622625369213307807",
                "92886736566340462731907656054698968589",
                "73286520249704886957742192927778620552",
                "272566268921517488772144767080575250691",
                "62501341652835320020077958032847389837",
                "270762509358935986249043554150792284407",
                "203343343778106405649140832532833575571",
                "182672448888178451594301525260568990574",
                "73264522482812473044239597644786023067",
                "63790997062493002300860364149241416488",
                "275310525381214255218470081705729756651",
                "194138451760890859241912641539836269685",
                "214317505453373753941989038469315183899",
                "795063021547843677924393395679858744",
                "150182530979840298716115572657921498262",
                "73233744968601644549082089859042827016",
                "158332771172661315691563424397245161985",
                "303428947035308491598555738953090059568",
                "114876555604121025260847798016508395627",
                "224325428016375777482160608903871479598",
                "7800933948177552484506566661052696194",
                "297777923742086989022480586282939446253",
                "6339339595980997012473534672428189127",
                "5252738383480155171738294145512933111",
                "338163891405691531408870065454235108487",
                "216213202058385302288736969327030204179",
                "236854995035053563886274428823746439234",
                "26605095798723525632320756931019623196",
                "151351206494432735155540845788624725406",
                "22556533209087331904446391100765045132",
                "310814531120933335853492630615329960861",
                "274813260599079563650629001380514686227",
                "177469644222833796942176173996715775620"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2025-53095-9b6fa52a",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/738ac93a0ec1cd10412d1f339968775f53bfefe0",
        "target": {
            "file": "src/confighttp.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "65058156632544642403916960319154969502",
            "length": 666
        },
        "id": "CVE-2025-53095-a573e6df",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/738ac93a0ec1cd10412d1f339968775f53bfefe0",
        "target": {
            "file": "src/confighttp.cpp",
            "function": "savePin"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "136167282673839804522677919396030473889",
            "length": 248
        },
        "id": "CVE-2025-53095-c1a6b14b",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/738ac93a0ec1cd10412d1f339968775f53bfefe0",
        "target": {
            "file": "src/confighttp.cpp",
            "function": "unpairAll"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "110806534449301370593198661245504513339",
            "length": 484
        },
        "id": "CVE-2025-53095-ce7dfd36",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/738ac93a0ec1cd10412d1f339968775f53bfefe0",
        "target": {
            "file": "src/confighttp.cpp",
            "function": "unpair"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "334238383764312290622779465174399309123",
            "length": 218
        },
        "id": "CVE-2025-53095-da0a070c",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/738ac93a0ec1cd10412d1f339968775f53bfefe0",
        "target": {
            "file": "src/confighttp.cpp",
            "function": "resetDisplayDevicePersistence"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "307486794218056738039587354096498897895",
            "length": 142
        },
        "id": "CVE-2025-53095-da2479e6",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/738ac93a0ec1cd10412d1f339968775f53bfefe0",
        "target": {
            "file": "src/confighttp.cpp",
            "function": "restart"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "221023767662896843606706740871669896896",
            "length": 1693
        },
        "id": "CVE-2025-53095-dabe1efe",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/738ac93a0ec1cd10412d1f339968775f53bfefe0",
        "target": {
            "file": "src/confighttp.cpp",
            "function": "savePassword"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "205319032420512166181579132159119385016",
            "length": 1384
        },
        "id": "CVE-2025-53095-f618ddb2",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/lizardbyte/sunshine/commit/738ac93a0ec1cd10412d1f339968775f53bfefe0",
        "target": {
            "file": "src/confighttp.cpp",
            "function": "saveApp"
        }
    }
]
vanir_signatures_modified
"2026-08-12T15:13:59Z"