CVE-2025-67229
CRITICALTodesktop Builder < 0.32.1 - Improper Certificate Validation
Title source: ruleDescription
An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to spoof backend responses by exploiting insufficient certificate validation.
Scores
CVSS v3
9.8
EPSS
0.0002
EPSS Percentile
3.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-295
Status
published
Products (1)
todesktop/builder
< 0.32.1
Published
Jan 23, 2026
Tracked Since
Feb 18, 2026