📦 Sunshine

by Lizardbyte

🔍 What is Sunshine?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-53095

CRITICAL CVSS 9.6 Jul 1, 2025

Sunshine's web UI lacks CSRF protection, allowing attackers to trick authenticated users into executing arbitrary OS commands with Administrator privileges via the 'Command Preparations' feature. This...

CVE-2025-10198

HIGH CVSS 7.8 Sep 9, 2025

Sunshine for Windows v2025.122.141614 has a DLL search-order hijacking vulnerability where attackers can place malicious DLLs in user-writable PATH directories. When Sunshine loads DLLs, it may execut...

CVE-2024-51738

HIGH CVSS 8.1 Jan 20, 2025

Sunshine versions 0.23.1 and earlier have a pairing protocol vulnerability that allows man-in-the-middle attacks during client pairing. An unauthenticated attacker could hijack legitimate pairing atte...

CVE-2024-45407

MEDIUM CVSS 6.5 Sep 10, 2024

This vulnerability in Sunshine game streaming software allows an attacker to gain unauthorized access by exploiting a flaw in the pairing process. During a man-in-the-middle attack, if a client attemp...

CVE-2024-31226

MEDIUM CVSS 4.9 May 16, 2024

This vulnerability in Sunshine game streaming software allows path interception attacks when terminating the service on Windows. Attackers can place malicious executables named 'Program.exe', 'Program...