Unity Editor 2019.1 through 6000.3 could allow remote...
High severity
Unreviewed
Published
Oct 3, 2025
to the GitHub Advisory Database
•
Updated Oct 3, 2025
Description
Published by the National Vulnerability Database
Oct 3, 2025
Published to the GitHub Advisory Database
Oct 3, 2025
Last updated
Oct 3, 2025
Unity Editor 2019.1 through 6000.3 could allow remote attackers to exploit file loading and Local File Inclusion (LFI) mechanisms via a crafted local application because of an Untrusted Search Path. This could permit unauthorized manipulation of runtime resources and third-party integrations. The issue could affect applications built using Unity and deployed across Android, Windows, macOS, and Linux platforms.
References