PT-2025-27501 · Sunshine · Sunshine

Reenignearcher

·

Published

2025-07-01

·

Updated

2025-08-22

·

CVE-2025-53096

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Sunshine versions prior to 2025.628.4510
Description: The issue concerns a lack of protection against clickjacking attacks in the web interface of Sunshine, a self-hosted game stream host for Moonlight. This allows an attacker to embed the Sunshine interface within a malicious website using an invisible or disguised iframe. If a user is tricked into interacting with the malicious page while authenticated, they may unknowingly perform actions within the Sunshine application without their consent.
Recommendations: For versions prior to 2025.628.4510, update to version 2025.628.4510 to resolve the issue. As a temporary workaround, consider restricting access to the web UI of Sunshine to minimize the risk of exploitation. Avoid using the Sunshine web interface on untrusted devices or networks until the issue is resolved.

Exploit

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2025-53096
GHSA-X97G-H2VP-G2C5

Affected Products

Sunshine