PT-2025-39202 · Sunshine · Sunshine

·

CVE-2025-54081

·

Published

2025-09-23

·

Updated

2025-10-08

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sunshine versions prior to 2025.923.33222
Description Sunshine, a self-hosted game stream host for Moonlight, is affected by an issue where the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory containing spaces, the Service Control Manager (SCM) may incorrectly interpret the path and potentially execute a malicious binary placed earlier in the search string.
Recommendations Update to version 2025.923.33222 or later.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54081
GHSA-6P7J-5V8V-W45H

Affected Products

Sunshine