August 10, 2026

CVE Watchtower


← Back to CVE List

CVE-2025-53594NVD

Vulnerability Summary

A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data.

We have already fixed the vulnerability in the following versions:
Qfinder Pro Mac 7.13.0 and later
Qsync for Mac 5.1.5 and later
QVPN Device Client for Mac 2.2.8 and later
Severity Level
MEDIUM(4.4)
Published Date
Jan 2, 2026
Last Modified
Jan 2, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.
CVSS v4.0 Base Metrics
Attack VectorLocal
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone