Authenticated Path Traversal in pyLoad Download Manager by pyLoad Team
CVE-2025-54140
7.5HIGH
What is CVE-2025-54140?
The pyLoad Download Manager has a path traversal vulnerability in its /json/upload endpoint that affects version 0.5.0b3.dev89. This flaw allows an authenticated attacker to manipulate the filename of uploaded files, enabling them to access directories outside the designated upload location. This can lead to the potential execution of arbitrary files on the server, resulting in serious risks such as remote code execution, privilege escalation, and system-wide compromises. The issue has been resolved in version 0.5.0b3.dev90.
Affected Version(s)
pyload >= 0.5.0b3.dev89, < 0.5.0b3.dev90