Vulnerability record · CVE-2024-31220 · published 5 April 2024
CVE-2024-31220: Lizardbyte sunshine path traversal vulnerability
Lizardbyte · Sunshine
Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely read arbitrary files without authentication due to a path traversal vulnerability. Users who exposed the Sunshine configuration web user interface outside of localhost may be affected, depending on firewall configuration. To exploit vulnerability, attacker could make an http/s request to the `node_modules` endpoint if user exposed Sunshine config web server to internet or attacker is on the LAN. Version 0.18.0 contains a patch for this issue. As a workaround, one may block access to Sunshine via firewall.
Description
Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely read arbitrary files without authentication due to a path traversal vulnerability. Users who exposed the Sunshine configuration web user interface outside of localhost may be affected, depending on firewall configuration. To exploit vulnerability, attacker could make an http/s request to the `node_modules` endpoint if user exposed Sunshine config web server to internet or attacker is on the LAN. Version 0.18.0 contains a patch for this issue. As a workaround, one may block access to Sunshine via firewall.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/LizardByte/Sunshine/releases/tag/v0.18.0 | Release Notes |
| https://github.com/LizardByte/Sunshine/security/advisories/GHSA-6rg7-7m3w-w5wc | Vendor Advisory |
| https://github.com/LizardByte/Sunshine/releases/tag/v0.18.0 | Release Notes |
| https://github.com/LizardByte/Sunshine/security/advisories/GHSA-6rg7-7m3w-w5wc | Vendor Advisory |
Track CVE-2024-31220 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-31220), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.