Authenticated Path Traversal in pyLoad Download Manager by pyLoad Team
CVE-2025-54140

7.5HIGH

Key Information:

Vendor

Pyload

Status
Vendor
CVE Published:
22 July 2025

What is CVE-2025-54140?

The pyLoad Download Manager has a path traversal vulnerability in its /json/upload endpoint that affects version 0.5.0b3.dev89. This flaw allows an authenticated attacker to manipulate the filename of uploaded files, enabling them to access directories outside the designated upload location. This can lead to the potential execution of arbitrary files on the server, resulting in serious risks such as remote code execution, privilege escalation, and system-wide compromises. The issue has been resolved in version 0.5.0b3.dev90.

Affected Version(s)

pyload >= 0.5.0b3.dev89, < 0.5.0b3.dev90

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.