CVE-2025-41255

HIGH

Cyberduck <9.1.6 - Mountain Duck <4.17.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.

Scores

CVSS v3 8.0
EPSS 0.0011
EPSS Percentile 28.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (2)
iterate GmbH/Cyberduck < 9.1.6
iterate GmbH/Mountain Duck < 4.17.5
Published Jun 25, 2025
Tracked Since Feb 18, 2026