SBA Security Advisory – Cyberduck and Mountain Duck – Improper Certificate Store Handling (CVE-2025-41255)
Vulnerability Overview
Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessary installing it to the Windows Certificate Store of the current user without any restrictions. This potentially allows attackers to bypass certificate-based authentication or authorization of other programs that trust this certificate store.
- Type of Vulnerability: CWE-266: Incorrect Privilege Assignment
- Fixed in Version: Cyberduck 9.1.7 and Mountain Duck 4.17.6
- CVE ID: CVE-2025-41255
- CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
- CVSS Base Score: 8.0 (High)
Recommended Countermeasure
We recommend to update to Cyberduck version 9.1.7 / Mountain Duck version 4.17.6 or later.
Links
Credits
Andreas Boll (SBA Research)
Thomas Kostal (SBA Research)