CNNVD-202508-112 Information

CNNVD ID

CNNVD-202508-112

CVE-2025-54792

  • CNNVD Published: 2025-08-01

Description (Chinese)

LocalSend是LocalSend开源的一个 AirDrop 的开源跨平台替代方案。 LocalSend 1.16.1及之前版本存在安全漏洞,该漏洞源于发现协议存在中间人攻击漏洞,可能导致文件传输拦截和修改。

Description (English)

LocalSend is an open source cross-platform alternative for AirDrop, a LocalSend open source. There is a security loophole in the LocalSend 1.15.1 and earlier versions, which stems from the discovery of an agreement with an attack loophole by an intermediary, which could lead to document transmission interception and modification.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

LocalSend

Published

2025-08-01

Last Modified

2026-02-24

References

https://github.com/localsend/localsend/releases/tag/v1.17.0 https://github.com/localsend/localsend/security/advisories/GHSA-424h-5f6m-x63f https://github.com/localsend/localsend/commit/e8635204ec782ded45bc7d698deb60f3c4105687 https://access.redhat.com/security/cve/cve-2025-54792

Patch

https://github.com/localsend/localsend/releases

Share on: