pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to SQL Injection. Attackers can modify or delete data in the database, causing data errors or loss. This issue has been patched in version 0.5.0b3.dev91.
History

Tue, 12 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 Aug 2025 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Pyload
Pyload pyload
Vendors & Products Pyload
Pyload pyload

Mon, 11 Aug 2025 22:45:00 +0000

Type Values Removed Values Added
Description pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to SQL Injection. Attackers can modify or delete data in the database, causing data errors or loss. This issue has been patched in version 0.5.0b3.dev91.
Title PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 7.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-11T22:21:52.225Z

Updated: 2025-08-12T15:49:56.057Z

Reserved: 2025-08-07T18:27:23.306Z

Link: CVE-2025-55156

cve-icon Vulnrichment

Updated: 2025-08-12T15:49:51.562Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-11T23:15:26.850

Modified: 2025-08-12T14:25:33.177

Link: CVE-2025-55156

cve-icon Redhat

No data.