CVE-2025-53594

A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Qfinder Pro Mac 7.13.0 and later Qsync for Mac 5.1.5 and later QVPN Device Client for Mac 2.2.8 and later
CVSS

No CVSS.

Configurations

No configuration.

History

02 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-02 16:16

Updated : 2026-01-02 16:45


NVD link : CVE-2025-53594

Mitre link : CVE-2025-53594

CVE.ORG link : CVE-2025-53594


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-59

Improper Link Resolution Before File Access ('Link Following')

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition