CVE-2025-53964
9.6GoldenDict · GoldenDict
GoldenDict versions 1.5.0 and 1.5.1 contain an exposed dangerous method that allows unauthorized file modification or reading when a user processes a crafted dictionary file.
Executive summary
A critical vulnerability in GoldenDict 1.5.0 and 1.5.1 allows for arbitrary file read and modification, posing a severe risk to system integrity.
Vulnerability
The application exposes an unsafe method that is triggered when a user adds a malicious dictionary file and subsequently performs a search, leading to potential unauthorized file system access.
Business impact
Successful exploitation could allow an attacker to read sensitive files or modify system configurations, leading to total system compromise. The high CVSS score of 9.6 reflects the severity of allowing arbitrary file operations.
Remediation
Immediate Action: Update to the latest available version of GoldenDict and avoid importing dictionary files from untrusted or unverified sources.
Proactive Monitoring: Monitor for unexpected file system access or modification events originating from the GoldenDict process.
Compensating Controls: Run the application with the principle of least privilege, ensuring the user account running GoldenDict has restricted access to sensitive system directories.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Users of GoldenDict should update their software immediately to the latest version. Exercise caution when downloading and importing dictionary files from external or untrusted repositories to prevent exploitation of this vulnerability.