CVE-2025-53096
Last modified
CVE-2025-53096 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability allows an attacker to embed the Sunshine interface within a malicious website using an invisible or disguised iframe. If a user is tricked into interacting (one or multiple clicks) with the malicious page while authenticated, they may unknowingly perform actions within the Sunshine application without their consent. This issue has been patched in version 2025.628.4510.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lizardbyte | Sunshine | < 2025.628.4510 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-53096?
How severe is CVE-2025-53096?
How do I fix CVE-2025-53096?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-5309The chat feature within Remote Support (RS) and Privileged R…9.8
- CVE-2025-53091WeGIA is an open source web manager with a focus on the Port…9.8
- CVE-2025-53092Strapi is an open source headless content management system.…6.5
- CVE-2025-53093TabberNeue is a MediaWiki extension that allows the wiki to …8.6
- CVE-2025-53094ESPAsyncWebServer is an asynchronous HTTP and WebSocket serv…8.7
- CVE-2025-53095Sunshine is a self-hosted game stream host for Moonlight. Pr…8.8
- CVE-2025-53097Roo Code is an AI-powered autonomous coding agent. Prior to …7.5
- CVE-2025-53098Roo Code is an AI-powered autonomous coding agent. The proje…8.1
- CVE-2025-53099Sentry is a developer-first error tracking and performance m…7.5
- CVE-2025-5310Dover Fueling Solutions ProGauge MagLink LX Consoles expose …9.8
- CVE-2025-53100RestDB's Codehooks.io MCP Server is an MCP server on the Cod…8.6
- CVE-2025-53101ImageMagick is free and open-source software used for editin…9.8
Are you affected by CVE-2025-53096?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
