VYPR
Medium severity6.1OSV Advisory· Published Jan 30, 2026· Updated Jun 17, 2026

CVE-2026-25154

CVE-2026-25154

Description

LocalSend is a free, open-source app that allows users to share files and messages with nearby devices over their local network without needing an internet connection. In versions up to and including 1.17.0, when a user initiates a "Share via Link" session, the LocalSend application starts a local HTTP server to host the selected files. The client-side logic for this web interface is contained in app/assets/web/main.js. Note that at [0], the handleFilesDisplay function constructs the HTML for the file list by iterating over the files received from the server. Commit 8f3cec85aa29b2b13fed9b2f8e499e1ac9b0504c contains a patch.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Localsend/LocalsendOSV3 versions
    v1.10.0, v1.11.0, v1.11.1, …+ 2 more
    • (no CPE)range: v1.10.0, v1.11.0, v1.11.1, …
    • cpe:2.3:a:localsend:localsend:*:*:*:*:*:*:*:*range: <=1.17.0
    • (no CPE)range: <=1.17.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.