CVE-2025-54792 Details
Description
LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without needing an internet connection. In versions 1.16.1 and below, a critical Man-in-the-Middle (MitM) vulnerability in the software's discovery protocol allows an unauthenticated attacker on the same local network to impersonate legitimate devices, silently intercepting, reading, and modifying any file transfer. This can be used to steal sensitive data or inject malware, like ransomware, into files shared between trusted users. The attack is hardly detectable and easy to implement, posing a severe and immediate security risk. This issue was fixed in version 1.17.0.
A critical Man-in-the-Middle (MitM) vulnerability has been identified in LocalSend versions through 1.16.1. This issue arises within the application's discovery protocol, which uses UDP multicast packets for device communication over local networks. The vulnerability allows an unauthenticated attacker to impersonate legitimate devices, intercepting, reading, and modifying file transfers between users. Exploitation of this flaw could lead to the theft of sensitive data or the injection of malware, such as ransomware, into shared files. The attack is difficult to detect and easy to execute, creating an immediate security risk.
Users can update to LocalSend version 1.17.0, which addresses the vulnerability by fixing the path traversal issue that allowed for the Man-in-the-Middle attack. The updated version is available on the LocalSend GitHub Releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/localsend/localsend/security/advisories/GHSA-424h-5f6m-x63f | CISA-ADP | ExploitVendor Advisory |
| https://github.com/localsend/localsend/commit/e8635204ec782ded45bc7d698deb60f3c4105687 | [email protected] | Patch |
| https://github.com/localsend/localsend/releases/tag/v1.17.0 | [email protected] | Release Notes |
| https://github.com/localsend/localsend/security/advisories/GHSA-424h-5f6m-x63f | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-300 | Channel Accessible by Non-Endpoint | [email protected] |
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| localsend localsend | < 1.17.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 3, 2025 | Initial Analysis | [email protected] |
| Aug 4, 2025 | CVE Modified | CISA-ADP |
| Aug 1, 2025 | New CVE Received | [email protected] |