PT-2025-32592 · Pyload · Pyload

Cyjhhh

·

Published

2025-08-11

·

Updated

2025-08-12

·

CVE-2025-55156

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: pyLoad versions prior to 0.5.0b3.dev91
Description: pyLoad, a free and open-source Download Manager written in pure Python, contains a SQL Injection issue in the add links parameter of the /json/add package API endpoint. This allows attackers to modify or delete data within the database, potentially leading to data errors or loss.
Recommendations: Update to version 0.5.0b3.dev91 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-55156
GHSA-PWH4-6R3M-J2RF

Affected Products

Pyload