216.73.217.22

CVE-2025-54140

· Published 22/07/2025 22:15 · Modified 22/07/2025 22:15

Labels: CVE-2025-54140 2025-07-22CVE-2025-54140CWE-22[email protected]

Essential information

Published
22/07/2025 22:15
Modified
22/07/2025 22:15
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS metrics

Description

pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated path traversal vulnerability exists in the /json/upload endpoint of pyLoad. By manipulating the filename of an uploaded file, an attacker can traverse out of the intended upload directory, allowing them to write arbitrary files to any location on the system accessible to the pyLoad process. This may lead to: Remote Code Execution (RCE), local privilege escalation, system-wide compromise, persistence, and backdoors. This is fixed in version 0.5.0b3.dev90.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pyload / pyload cpe:2.3:a:pyload:pyload:0.5.0b3.dev89:*:*:*:*:*:*:*
pyload / pyload cpe:2.3:a:pyload:pyload:0.5.0b3.dev90:*:*:*:*:*:*:*

References