CVE-2026-25039

Source
https://cve.org/CVERecord?id=CVE-2026-25039
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25039.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-25039
Aliases
  • GHSA-qx56-wxpm-j4m6
Published
2026-07-20T14:53:13.505Z
Modified
2026-07-22T05:29:40.626327957Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
The application evaluate UNC path in workspace name
Details

Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creating a vulnerability if that workspace name is a UNC path. When creating mountpoint in the windows filesystem to mount the workspace of an organization, the application does not sanitize the workspace name. The cause issue if the workspace name evaluate to a UNC path since it's allowed for the name to containt \ char. If the UNC path is invalid (or the targeted resource is not available) the application become unresponsive otherwise the system will interact with the mounted UNC path allowing the attacker to retrieve to [NTLM] hash.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25039.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-40"
    ]
}
References

Affected packages

Git / github.com/scille/parsec-cloud

Affected ranges

Type
GIT
Repo
https://github.com/scille/parsec-cloud
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.3.3-rc.0"
        }
    ]
}

Affected versions

Other
test-annotated
v0.*
v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.10.4
v0.11.0
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.9.0
v0.9.1
v0.9.2
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.1.0
v1.1.1
v1.1.2
v1.10.0
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.12.0
v1.13.0
v1.14.0
v1.14.0-rc1
v1.14.0-rc2
v1.14.0-rc3
v1.14.0-rc4
v1.14.0-rc5
v1.15.0
v1.15.2
v1.2.0
v1.2.1
v1.3.0
v1.4.0
v1.5.0
v1.6.0
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.9.0
v1.9.1
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.3.0
v2.3.1
v2.4.0
v2.4.1
v2.4.2
v2.5.0
v2.5.1
v2.5.2
v2.5.3
v2.5.4
v2.7.0-rc5
v2.8.0
v2.8.0-rc1
v2.8.1
v2.9.0
v2.9.0-rc1
v2.9.1
v2.9.2
v3.*
v3.0.0-alpha
v3.3.0
v3.3.0-rc.10
v3.3.0-rc.11
v3.3.0-rc.12
v3.3.0-rc.6
v3.3.0-rc.7
v3.3.0-rc.8
v3.3.0-rc.9
v3.3.1
v3.3.1-rc.0
v3.3.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25039.json"