Get real-time updates on Telegram
CVE-2025-59489: editor 2017.1.2p4+, 2017.2.0p4+, 2017.3.0b9+; +1 more affected products
CVE-2025-59489. CVSS 3.1 base score 7.4 (HIGH, Vendor/CNA). EPSS 0.00644 (percentile 0.49301), scored 2026-10-08.
Affected technology
editor · from 2017.4 (inclusive), through 2018.4 (inclusive)
unity
editor · from 2019.1 (inclusive), before 2019.1.15f1 (exclusive)
unity
editor · from 2019.2 (inclusive), before 2019.2.23f1 (exclusive)
unity
editor · from 2019.3 (inclusive), through 2019.3.17f1 (inclusive)
unity
editor · from 2019.4 (inclusive), before 2019.4.41f1 (exclusive)
unity
editor · from 2020.1 (inclusive), before 2020.1.18f1 (exclusive)
unity
editor · from 2020.2 (inclusive), before 2020.2.8f1 (exclusive)
unity
editor · from 2020.3 (inclusive), before 2020.3.49f1 (exclusive)
unity
editor · from 2021.1 (inclusive), before 2021.1.29f1 (exclusive)
unity
editor · from 2021.2 (inclusive), before 2021.2.20f1 (exclusive)
unity
editor · from 2021.3 (inclusive), before 2021.3.45f2 (exclusive)
unity
editor · from 2022.1 (inclusive), before 2022.1.25f1 (exclusive)
unity
editor · from 2022.2 (inclusive), before 2022.2.23f1 (exclusive)
unity
editor · from 2022.3 (inclusive), before 2022.3.62f2 (exclusive)
unity
editor · from 2023.1 (inclusive), before 2023.1.22f1 (exclusive)
unity
editor · from 2023.2 (inclusive), before 2023.2.22f1 (exclusive)
unity
editor · from 6000.0 (inclusive), before 6000.0.58f2 (exclusive)
unity
editor · from 6000.1 (inclusive), before 6000.1.17f1 (exclusive)
unity
editor · from 6000.2 (inclusive), before 6000.2.6f2 (exclusive)
unity
editor · from 6000.3 (inclusive), before 6000.3.0b4 (exclusive)
unity
editor · 2017.1.2p4+
unity
editor · 2017.2.0p4+
unity
editor · 2017.3.0b9+
unity
Unity Editor · 6000.3 to before 6000.3.0b4, 6000.2 to before 6000.2.6f2, 6000.0 LTS to before 6000.0.58f2, 2022.3 xLTS to before 2022.3.67f2, 2021.3 xLTS to before 2021.3.56f2, 6000.1 to before 6000.1.17f1, 2023.2 to before 2023.2.22f1, 2023.1 to before 2023.1.22f1, 2022.3 LTS to before 2022.3.62f2, 2022.2 to before 2022.2.23f1, 2022.1 to before 2022.1.25f1, 2021.3 LTS to before 2021.3.45f2, 2021.2 to before 2021.2.20f1, 2021.1 to before 2021.1.29f1, 2020.3 to before 2020.3.49f1, 2020.2 to before 2020.2.8f1, 2020.1 to before 2020.1.18f1, 2019.4 LTS to before 2019.4.41f1, 2019.3 to before 2019.3.17f1, 2019.2 to before 2019.2.23f1, 2017.1.2p4 to before 2019.1.15f1
Unity3D
Description’s affected range: before 2025-10-02 on Android, Windows, macOS, and Linux
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Local · No privileges required · No user interaction required
Attack conditions (Source advisory, CVSS 3.1): Local · No privileges required · No user interaction required
What an attacker can do
Vendor/CNA’s CVSS 3.1 assessment (base score 7.4/10) rates confidentiality, integrity and availability impact as high. Source advisory’s CVSS 3.1 assessment (base score 8.4/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-88, CWE-426
- CCR priority
- 29.8 /100 (P4)
- CVSS 3.1
- 7.4 /10 · CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H · Vendor/CNA
- EPSS
- 0.00644 · percentile 0.49301 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-59489.html