Cross-Site Request Forgery Vulnerability in Sunshine Game Stream Host
CVE-2025-53095

9.7CRITICAL

Key Information:

Vendor

Lizardbyte

Status
Vendor
CVE Published:
1 July 2025

What is CVE-2025-53095?

The Sunshine application, a self-hosted game stream host for Moonlight, is vulnerable to Cross-Site Request Forgery (CSRF) attacks prior to version 2025.628.4510. This vulnerability allows malicious actors to craft deceptive web pages that, when accessed by an authenticated user, trigger unintended actions within the Sunshine application. Exploiting this flaw can lead to unauthorized OS command execution, particularly misusing the 'Command Preparations' feature, which can result in the execution of arbitrary commands with Administrator privileges. This security issue has been addressed in version 2025.628.4510, necessitating users to update their installations to safeguard against potential exploitation.

Affected Version(s)

Sunshine < 2025.628.4510

References

CVSS V3.1

Score:
9.7
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53095 : Cross-Site Request Forgery Vulnerability in Sunshine Game Stream Host