CVE-2025-41255: Cyberduck and Mountain Duck - Improper Certificate Store Handling
Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions.
This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41255?
CVE-2025-41255 is considered a high-severity vulnerability due to improper handling of TLS certificate pinning.
How do I fix CVE-2025-41255?
To fix CVE-2025-41255, update Cyberduck to version 9.1.7 or greater and Mountain Duck to version 4.17.6 or greater.
What systems are affected by CVE-2025-41255?
CVE-2025-41255 affects Cyberduck versions up to 9.1.6 and Mountain Duck versions up to 4.17.5.
What does CVE-2025-41255 vulnerability affect?
CVE-2025-41255 affects the handling of TLS certificate pinning for untrusted certificates in Cyberduck and Mountain Duck.
Can CVE-2025-41255 lead to security breaches?
Yes, CVE-2025-41255 can potentially lead to security breaches by allowing untrusted certificates to be installed without proper restrictions.