Vulnerability record · CVE-2024-31221 · published 8 April 2024
CVE-2024-31221: Lizardbyte sunshine vulnerability
Lizardbyte · Sunshine
Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a workaround, restarting Sunshine after unpairing all devices prevents the vulnerability.
Description
Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a workaround, restarting Sunshine after unpairing all devices prevents the vulnerability.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/LizardByte/Sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e | Patch |
| https://github.com/LizardByte/Sunshine/issues/2305 | ExploitIssue Tracking |
| https://github.com/LizardByte/Sunshine/pull/2365 | Issue TrackingPatch |
| https://github.com/LizardByte/Sunshine/security/advisories/GHSA-v8gw-jw28-v55m | Vendor Advisory |
| https://github.com/LizardByte/Sunshine/commit/b7aa8119f1471844dccdf73a8b6f7efc9baddb5e | Patch |
| https://github.com/LizardByte/Sunshine/issues/2305 | ExploitIssue Tracking |
| https://github.com/LizardByte/Sunshine/pull/2365 | Issue TrackingPatch |
| https://github.com/LizardByte/Sunshine/security/advisories/GHSA-v8gw-jw28-v55m | Vendor Advisory |
Track CVE-2024-31221 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-31221), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.