Home

Description

Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.

PUBLISHED Reserved 2025-04-16 | Published 2025-06-25 | Updated 2025-06-25 | Assigner sba-research




HIGH: 8.0CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

Problem types

CWE-266: Incorrect Privilege Assignment

Product status

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Credits

Thomas Kostal finder

Andreas Boll finder

References

github.com/...erduck/security/advisories/GHSA-vjjc-grpp-m655 exploit

github.com/...1_Cyberduck_Mountain_Duck_Certificate_Handling exploit

github.com/...1_Cyberduck_Mountain_Duck_Certificate_Handling third-party-advisory

github.com/...erduck/security/advisories/GHSA-vjjc-grpp-m655 vendor-advisory

cve.org (CVE-2025-41255)

nvd.nist.gov (CVE-2025-41255)

Download JSON