CVE-2025-53095 Details
Description
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker to craft a malicious web page that, when visited by an authenticated user, can trigger unintended actions within the Sunshine application on behalf of that user. Specifically, since the application does OS command execution by design, this issue can be exploited to abuse the "Command Preparations" feature, enabling an attacker to inject arbitrary commands that will be executed with Administrator privileges when an application is launched. This issue has been patched in version 2025.628.4510.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Sunshine, a self-hosted game stream host for Moonlight, prior to version 2025.628.4510. The issue arises because the web UI lacks adequate protection against CSRF attacks, allowing an attacker to create a malicious web page that, when accessed by an authenticated user, can perform unintended actions within the Sunshine application on that user's behalf. This vulnerability is particularly concerning because the application is designed to execute operating system commands, which can be exploited to misuse the 'Command Preparations' feature. As a result, an attacker could inject arbitrary commands that would be executed with Administrator privileges when an application is launched.
Users can update to Sunshine version 2025.628.4510 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lizardbyte sunshine | < 2025.628.4510 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 22, 2025 | Initial Analysis | [email protected] |
| Jul 1, 2025 | New CVE Received | [email protected] |