PT-2025-31885 · Pyload · Pyload

Ikhsanzdev

+1

·

Published

2025-08-01

·

Updated

2025-10-09

·

CVE-2025-54802

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions pyLoad versions 0.5.0b3.dev89 and below
Description pyLoad is a free and open-source Download Manager written in pure Python. A path traversal vulnerability exists in the pyLoad-ng CNL Blueprint via the package parameter, allowing arbitrary file write and potentially leading to Remote Code Execution (RCE). The /addcrypted endpoint in pyload-ng is susceptible to an unsafe path construction vulnerability, enabling unauthenticated attackers to write arbitrary files outside the designated storage directory. This can be exploited to overwrite critical system files, such as cron jobs and systemd services, resulting in privilege escalation and remote code execution as root.
Recommendations Update to version 0.5.0b3.dev90.

Exploit

Fix

LPE

RCE

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-07564
CVE-2025-54802
GHSA-48RP-JC79-2264

Affected Products

Pyload