Unity Found to Have Critical Vulnerability — V Rising Developers Issue Official Statement

Unity Found to Have Critical Vulnerability — V Rising Developers Issue Official Statement

Hennadiy Chemеris
October 3, 2025, 05:39 PM

Unity Technologies has issued an official warning about a critical vulnerability in the Unity engine, affecting a wide range of editor versions and games built on the platform. The issue, identified as CVE-2025-59489, is classified as a high-severity vulnerability with a CVSS score of 8.4.

Discovered by RyotaK from GMO Flatt Security Inc. on June 4, 2025, the vulnerability is related to unsafe file loading and local file inclusion depending on the operating system. This could lead to arbitrary code execution or unauthorized access with the same privileges as the application.

According to Unity, the vulnerability impacts apps and games on Android, Windows, Linux, and macOS. Projects using custom URI handlers on Windows are considered especially at risk.

Unity emphasized that, so far, there have been no reports of the vulnerability being exploited or any harm caused to users. However, the company has released patches and is urging developers to update immediately.

The patched versions of Unity Editor include:

  • 6000.3.0b4;
  • 6000.2.6f2;
  • 6000.0.58f2;
  • Updates for the 2021, 2022, and 2023 branches.

Even older versions starting from Unity 2019.1 have received patches, though earlier releases will remain unsupported.

Several well-known games have already been updated with security fixes, including Cities Skylines 2 and Two Point Museum. According to Unity, some projects may have been updated "silently" without official announcements.

The developers of V Rising have also responded to the situation, warning players about the risks.

It's recently been found by Unity that there is a vulnerability as old as 2017 that could potentially be exploited in games made with Unity. We've already patched the issue on clients and are currently working to patch it on the server client as well.

We highly recommend patching your game and dedicated server client as soon as it's available, as well as being very cautious about any mods you download until you verify they're secure.

Be safe out there and take care.
— Stunlock Studios

What players and developers should do:

  • Players: Update the client for any Unity-based games as soon as possible and be cautious with mods;
  • Server admins: Apply patches as soon as they become available;
  • Developers: Rebuild projects using the latest Unity Editor versions or apply binary patches.

Unity noted that all fixes are already available through Unity Hub, and recommends updating without delay.

By the way, last year Unity launched the sixth version of its engine without the controversial payment rules.

    About the author
    Comments0