Vulnerability Description
Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with renderer-context access to invoke external protocol handlers without sufficient validation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Todesktop | Builder | < 0.33.0 |
Related Weaknesses (CWE)
References
- https://www.todesktop.com/changelogProductRelease Notes
- https://www.todesktop.com/security/advisories/TDSA-2025-002Vendor Advisory
FAQ
What is CVE-2025-67230?
CVE-2025-67230 is a vulnerability with a CVSS score of 7.1 (HIGH). Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with renderer-context access to invoke external protocol handlers without sufficient validat...
How severe is CVE-2025-67230?
CVE-2025-67230 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-67230?
Check the references section above for vendor advisories and patch information. Affected products include: Todesktop Builder.