CVE-2026-25154 | LocalSend up to 1.17.0 app/assets/web/main.js handleFilesDisplay cross site scripting (GHSA-34v6-52hh-x4r4 / EUVD-2026-5001)
A vulnerability labeled as problematic has been found in LocalSend up to 1.17.0. Affected is the function handleFilesDisplay of the file app/assets/web/main.js. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-25154. The attack may be launched remotely. There is no exploit available.
Applying a patch is advised to resolve this issue.