ZDI-25-1070: TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of the Electron framework. The product loads a script file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-14498.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-1070?
The severity of ZDI-25-1070 is high with a CVSS score of 7.8.
How do I fix ZDI-25-1070?
To fix ZDI-25-1070, update TradingView Desktop to the latest version to mitigate the vulnerability.
What type of vulnerability is ZDI-25-1070?
ZDI-25-1070 is classified as a local privilege escalation vulnerability.
What software is affected by ZDI-25-1070?
ZDI-25-1070 affects the TradingView Desktop application.
What must an attacker do to exploit ZDI-25-1070?
An attacker must first execute low-privileged code on the target system to exploit ZDI-25-1070.