Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2025-59334

9.6 · CRITICAL
Published Sep 16, 2025 mohammadzain2008 CWE-347 EPSS 0.43% (36th pctl)

Overview

CVE-2025-59334 is a critical-severity vulnerability affecting mohammadzain2008 linkr. It was published on September 16, 2025 and has a CVSS 3.1 base score of 9.6 (CRITICAL).

This vulnerability has a CVSS 3.1 base score of 9.6, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not verify the integrity or authenticity of .linkr manifest files before using their contents, allowing a tampered manifest to inject arbitrary file entries into a package distribution. An attacker can modify a generated .linkr manifest (for example by adding a new entry with a malicious URL) and when a user runs the extract command the client downloads the attacker-supplied file without verification. This enables arbitrary file injection and creates a potential path to remote code execution if a downloaded malicious binary or script is later executed. Version 2.0.1 adds a manifest integrity check that compares the checksum of the original author-created manifest to the one being extracted and aborts on mismatch, warning if no original manifest is hosted. Users should update to 2.0.1 or later. As a workaround prior to updating, use only trusted .linkr manifests, manually v

Remediation

Check the references section for vendor advisories and patches from mohammadzain2008. Update linkr to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
mohammadzain2008 linkr >= 0, < 2.0.1 Affected

Frequently Asked Questions

What is CVE-2025-59334?

CVE-2025-59334 is a critical-severity vulnerability affecting mohammadzain2008 linkr. It was published on September 16, 2025 and has a CVSS 3.1 base score of 9.6 (CRITICAL).

How severe is CVE-2025-59334?

This vulnerability has a CVSS 3.1 base score of 9.6, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2025-59334?

Check the references section for vendor advisories and patches from mohammadzain2008. Update linkr to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2025-59334?

CyberStrike's AI-powered security agents can automatically detect CVE-2025-59334 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.