Cross-Site Request Forgery Vulnerability in Sunshine Game Stream Host
CVE-2025-53095
9.7CRITICAL
What is CVE-2025-53095?
The Sunshine application, a self-hosted game stream host for Moonlight, is vulnerable to Cross-Site Request Forgery (CSRF) attacks prior to version 2025.628.4510. This vulnerability allows malicious actors to craft deceptive web pages that, when accessed by an authenticated user, trigger unintended actions within the Sunshine application. Exploiting this flaw can lead to unauthorized OS command execution, particularly misusing the 'Command Preparations' feature, which can result in the execution of arbitrary commands with Administrator privileges. This security issue has been addressed in version 2025.628.4510, necessitating users to update their installations to safeguard against potential exploitation.
Affected Version(s)
Sunshine < 2025.628.4510