Synology BeeDrive for Desktop Origin Validation Error Vulnerability Allowing Arbitrary File Writing

Vulnerability

An origin validation error vulnerability exists in Synology BeeDrive for desktop, prior to version 1.4.3-13973. This vulnerability allows local users to write arbitrary files containing non-sensitive information, through unspecified vectors.

Impact

Exploitation of this vulnerability could lead to unauthorized writing of files with non-sensitive information, potentially causing data management issues or interference with other applications.

Remediation

Users are advised to upgrade to Synology BeeDrive for desktop version 1.4.3-13973 or above.

Added: Dec 4, 2025, 4:17 PM
Updated: Dec 4, 2025, 5:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
3.3
remediation
7.7
relevance
1.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.