PT-2025-43406 · Aiomysql+2 · Aiomysql+2

Published

2025-10-22

·

Updated

2025-11-24

·

CVE-2025-62611

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions aiomysql versions prior to 0.3.0
Description aiomysql does not properly validate client-side settings before transmitting local files to a MySQL server. This allows a malicious server to request arbitrary files from the client by sending a LOAD LOCAL instruction packet, effectively bypassing security measures. A rogue MySQL server can emulate authorization, ignore client flags, and steal files from the client. This issue impacts environments connecting to untrusted or compromised MySQL servers. A proof-of-concept demonstrates the ability to read files from the client machine using a rogue MySQL server and the aiomysql library, even when the local infile option is explicitly disabled on the client side. The rogue server logs successful file reads and saves the contents to a designated directory.
Recommendations Versions prior to 0.3.0 should be updated to version 0.3.0 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-15607
CVE-2025-62611
GHSA-R397-FF8C-WV2G
OESA-2025-2616
OESA-2025-2617
OESA-2025-2618
OESA-2025-2619
OESA-2025-2675

Affected Products

Debian
Red Os
Aiomysql