CVE-2026-25154Disclosure(localsend / localsend)

LOWCVSS 6.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LocalSend is a free, open-source app that allows users to share files and messages with nearby devices over their local network without needing an internet connection. In versions up to and including 1.17.0, when a user initiates a "Share via Link" session, the LocalSend application starts a local HTTP server to host the selected files. The client-side logic for this web interface is contained in `app/assets/web/main.js`. Note that at [0], the `handleFilesDisplay` function constructs the HTML for the file list by iterating over the files received from the server. Commit 8f3cec85aa29b2b13fed9b2f8e499e1ac9b0504c contains a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • localsend

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
localsend

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-01-30: 2Technical Details · 2026-01-30: 101-30
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-25154 LocalSend is a free, open-source app that allows users to share files and messages with nearby devices over their local network without needing an internet connection… https://www.cve.org/CVERecord?id=CVE-2026-25154

    Post summary

    The text merely references the CVE for LocalSend with a link, providing no further details.

    00000634
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25154 LocalSend File Sharing App Remote Code Execution via Malicious File List HTML https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25154

    Post summary

    The entry announces CVE-2026-25154, a remote code execution flaw in LocalSend triggered by a malicious File List HTML file, with no PoC, exploit, active exploitation, or patch information provided.

    0000088
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applocalsendlocalsend---

Explore more