CVE-2025-54081

MEDIUM

Sunshine <2025.923.33222 - Path Traversal

Title source: llm
STIX 2.1

Description

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose name includes a space, the Service Control Manager (SCM) interprets the path incrementally and may execute a malicious binary placed earlier in the search string. This issue has been patched in version 2025.923.33222.

Scores

CVSS v3 6.7
EPSS 0.0002
EPSS Percentile 3.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
lizardbyte/sunshine 0.10.0 - 2025.923.33222
Published Sep 23, 2025
Tracked Since Feb 18, 2026