PT-2025-34274 · Pyload · Pyload

Cyjhhh

·

Published

2025-08-21

·

Updated

2025-08-21

·

CVE-2025-57751

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: pyLoad versions prior to 0.5.0b3.dev92
Description: The jk parameter in the pyLoad CNL Blueprint lacks proper verification. This allows a user-supplied jk parameter to be directly passed to dykpy.evaljs(), leading to full server CPU utilization and rendering the web-ui unresponsive. The vulnerable code is located in cnl blueprint.py and misc.py. The /flash/addcrypted2 API endpoint is affected. The jk parameter is vulnerable.
Recommendations: Update pyLoad to version 0.5.0b3.dev92 or later.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2025-57751
GHSA-9GJJ-6GJ7-C4WJ

Affected Products

Pyload