LocalSend File Transfer Vulnerability in Open-Source Application
CVE-2025-27142
What is CVE-2025-27142?
LocalSend is a free, open-source application designed for secure file sharing over local networks without the need for an internet connection. However, prior to version 1.17.0, it exhibited a critical flaw in its handling of file transfer requests. Specifically, the application failed to properly sanitize file paths in its POST /api/localsend/v2/prepare-upload and POST /api/localsend/v2/upload endpoints. This oversight allowed attackers to send crafted file transfer requests that could manipulate file locations on the user’s system, resulting in arbitrary file writes and potential remote command execution. Particularly concerning is the use of the 'Quick Save' feature, which could execute these malicious actions without user consent or intervention. This vulnerability has been addressed in version 1.17.0, making immediate updates essential for users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
localsend < 1.17.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
