PT-2025-31704 · Localsend · Localsend

Deepunk42

·

Published

2025-08-01

·

Updated

2025-08-04

·

CVE-2025-54792

CVSS v4.0

9.3

Critical

VectorAV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions LocalSend versions 1.16.1 and earlier
Description LocalSend is an open-source application designed for secure file and message sharing between nearby devices on local networks without requiring an internet connection. A critical Man-in-the-Middle (MitM) vulnerability exists in the software’s discovery protocol, allowing an unauthenticated attacker on the same local network to impersonate legitimate devices. This enables the attacker to silently intercept, read, and modify any file transfer. The vulnerability can be exploited to steal sensitive data or inject malware, such as ransomware, into files shared between trusted users. The attack is difficult to detect and easy to implement, posing a severe and immediate security risk.
Recommendations Update LocalSend to version 1.17.0 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2025-54792
GHSA-424H-5F6M-X63F

Affected Products

Localsend