CVE-2025-53594

CVSS

No CVSS.

A

path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Qfinder Pro Mac 7.13.0 and later Qsync for Mac 5.1.5 and later QVPN Device Client for Mac 2.2.8 and later

Configurations

No configuration.

History

02 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-02 16:16

Updated : 2026-01-02 16:45


NVD link : CVE-2025-53594

Mitre link : CVE-2025-53594

CVE.ORG link : CVE-2025-53594


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-59

Improper Link Resolution Before File Access ('Link Following')

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition