PT-2025-50567 · Pyrofork · Pyrofork
Published
2025-12-11
·
Updated
2025-12-12
·
CVE-2025-67720
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Pyrofork versions 2.3.68 and earlier
Description
Pyrofork is an asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames received from Telegram messages before using them in file path construction within the
download media method. When downloading media without a custom filename, the method uses the file name attribute from the media object, which originates from Telegram’s DocumentAttributeFilename and is controlled by the message sender. This can lead to a path traversal issue.Recommendations
Update to version 2.3.69 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyrofork