CVE-2025-13131

A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\Sonarr\bin\Sonarr.Console.exe of the component Service. Performing manipulation results in incorrect default permissions. The attack is only possible with local access. The vendor confirms this vulnerability but classifies it as a "low severity issue due to the default service user being used as it would either require someone to intentionally change the service to a highly privileged account or an attacker would need an admin level account". It is planned to fix this issue in the next major release v5.
Configurations

No configuration.

History

13 Nov 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-13 22:15

Updated : 2025-11-14 16:42


NVD link : CVE-2025-13131

Mitre link : CVE-2025-13131

CVE.ORG link : CVE-2025-13131


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment

CWE-276

Incorrect Default Permissions