CVE-2025-67231: Todesktop Builder

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

A reflected cross-site scripting (XSS) vulnerability in ToDesktop Builder v0.33.1 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload.

Affected products

  • Todesktop Builder: before 0.33.1 (fixed in 0.33.1)

Published 2026-01-23. Last modified 2026-06-17.