Authenticated Path Traversal in pyLoad Download Manager by pyLoad Team
CVE-2025-54140
What is CVE-2025-54140?
The pyLoad Download Manager has a path traversal vulnerability in its /json/upload endpoint that affects version 0.5.0b3.dev89. This flaw allows an authenticated attacker to manipulate the filename of uploaded files, enabling them to access directories outside the designated upload location. This can lead to the potential execution of arbitrary files on the server, resulting in serious risks such as remote code execution, privilege escalation, and system-wide compromises. The issue has been resolved in version 0.5.0b3.dev90.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
pyload >= 0.5.0b3.dev89, < 0.5.0b3.dev90
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
