PT-2025-38060 · Linkr · Linkr

Mohammadzain2008

·

Published

2025-09-16

·

Updated

2025-09-17

·

CVE-2025-59334

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linkr versions through 2.0.0
Description Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr does not verify the integrity or authenticity of .linkr manifest files before using their contents, allowing a tampered manifest to inject arbitrary file entries into a package distribution. An attacker can modify a .linkr manifest and, when a user runs the extract command, the client downloads the attacker-supplied file without verification. This enables arbitrary file injection and creates a potential path to remote code execution if a downloaded malicious binary or script is later executed.
Recommendations Update to version 2.0.1 or later. As a workaround prior to updating, use only trusted .linkr manifests. Manually verify manifest integrity. Host manifests on trusted servers.

Exploit

Fix

RCE

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2025-59334
GHSA-6WPH-MPV2-29XV

Affected Products

Linkr