This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19096 | Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5. |
Wed, 25 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Jun 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5. | |
| Title | Cyberduck and Mountain Duck - Improper Certificate Store Handling | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: sba-research
Published:
Updated: 2025-06-25T13:33:27.985Z
Reserved: 2025-04-16T09:37:50.630Z
Link: CVE-2025-41255
Updated: 2025-06-25T13:33:19.194Z
Status : Deferred
Published: 2025-06-25T10:15:21.783
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-41255
No data.
OpenCVE Enrichment
No data.
EUVD