We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.
Reserved 2025-04-16 | Published 2025-06-25 | Updated 2025-06-25 | Assigner sba-researchCWE-266: Incorrect Privilege Assignment
Thomas Kostal
Andreas Boll
github.com/...1_Cyberduck_Mountain_Duck_Certificate_Handling
github.com/...erduck/security/advisories/GHSA-vjjc-grpp-m655
Support options