CVE-2025-67229 Details
Description
An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to spoof backend responses by exploiting insufficient certificate validation.
A vulnerability allowing improper certificate validation has been identified in ToDesktop Builder versions prior to 0.32.1. This issue enables an unauthenticated, on-path attacker to spoof backend responses by exploiting the application's insufficient validation of TLS/SSL certificates. As a result, an attacker in a privileged network position could intercept and modify communications between the application and backend services, potentially leading to unauthorized data disclosure, integrity violations, or the injection of malicious content.
Users with automatic security updates enabled have already received the patch. For those who have disabled automatic updates, ToDesktop Builder can be manually updated to version 0.32.1.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.todesktop.com/changelog | [email protected] | ProductRelease Notes |
| https://www.todesktop.com/security/advisories/TDSA-2025-001 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| todesktop builder | < 0.32.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 29, 2026 | Initial Analysis | [email protected] |
| Jan 23, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | New CVE Received | [email protected] |