Arbitrary Code Execution Vulnerability in pyload-ng
CVE-2024-39205

Currently unrated

Key Information:

Vendor
pyload-ng
Vendor
CVE Published:
28 October 2024

Badges

👾 Exploit Exists🟡 Public PoC🟣 EPSS 60%

Summary

An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

60% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

.