SQL Injection Vulnerability in pyLoad Download Manager
CVE-2025-55156

7.8HIGH

Key Information:

Vendor

Pyload

Status
Vendor
CVE Published:
11 August 2025

What is CVE-2025-55156?

The pyLoad Download Manager, a free and open-source application written in Python, has a vulnerability in the /json/add_package API endpoint. Specifically, the 'add_links' parameter is susceptible to SQL Injection, potentially allowing attackers to manipulate or erase data within the database. This could lead to significant data errors or loss. Users are encouraged to upgrade to version 0.5.0b3.dev91 or later to mitigate this issue, which has been addressed in recent patches.

Affected Version(s)

pyload < 0.5.0b3.dev91

References

CVSS V4

Score:
7.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55156 : SQL Injection Vulnerability in pyLoad Download Manager