PT-2025-27501 · Sunshine · Sunshine
Reenignearcher
·
Published
2025-07-01
·
Updated
2025-08-22
·
CVE-2025-53096
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Sunshine versions prior to 2025.628.4510
Description:
The issue concerns a lack of protection against clickjacking attacks in the web interface of Sunshine, a self-hosted game stream host for Moonlight. This allows an attacker to embed the Sunshine interface within a malicious website using an invisible or disguised iframe. If a user is tricked into interacting with the malicious page while authenticated, they may unknowingly perform actions within the Sunshine application without their consent.
Recommendations:
For versions prior to 2025.628.4510, update to version 2025.628.4510 to resolve the issue. As a temporary workaround, consider restricting access to the web UI of Sunshine to minimize the risk of exploitation. Avoid using the Sunshine web interface on untrusted devices or networks until the issue is resolved.
Exploit
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sunshine