« Volver al listado

CVE-2025-54140

Estado: AplazadaAlta (7.5)—

pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated path traversal vulnerability exists in the /json/upload endpoint of pyLoad. By manipulating the filename of an uploaded file, an attacker can traverse out of the intended upload directory, allowing them to write arbitrary files to any location on the system accessible to the pyLoad process. This may lead to: Remote Code Execution (RCE), local privilege escalation, system-wide compromise, persistence, and backdoors. This is fixed in version 0.5.0b3.dev90.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Path traversal autenticado en endpoint de aplicación web (AV:N, PR autenticado) permite escritura de archivos arbitrarios causando RCE y persistencia de backdoors; vector de red sin privilegios requeridos iniciales es T1190.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-54140",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-54140",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-23T18:28:30.704049Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "pyload",
          "product": "pyload",
          "versions": [
            {
              "status": "affected",
              "version": ">= 0.5.0b3.dev89, < 0.5.0b3.dev90"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-07-22T22:15:38.390",
  "references": [
    {
      "url": "https://github.com/pyload/pyload/blob/df094db67ec6e25294a9ac0ddb4375fd7fb9ba00/src/pyload/webui/app/blueprints/json_blueprint.py#L109",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/pyload/pyload/commit/fc4b136e9c4e7dcbb8e467ae802cb2c3f70a71b0",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/pyload/pyload/security/advisories/GHSA-xqpg-92fq-grfg",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated path traversal vulnerability exists in the /json/upload endpoint of pyLoad. By manipulating the filename of an uploaded file, an attacker can traverse out of the intended upload directory, allowing them to write arbitrary files to any location on the system accessible to the pyLoad process. This may lead to: Remote Code Execution (RCE), local privilege escalation, system-wide compromise, persistence, and backdoors. This is fixed in version 0.5.0b3.dev90."
    },
    {
      "lang": "es",
      "value": "pyLoad es un gestor de descargas gratuito y de código abierto escrito en Python puro. En la versión 0.5.0b3.dev89, existe una vulnerabilidad de path traversal autenticado en el endpoint /json/upload de pyLoad. Al manipular el nombre de un archivo subido, un atacante puede cruzar fuera del directorio de carga previsto, lo que le permite escribir archivos arbitrarios en cualquier ubicación del sistema accesible para el proceso pyLoad. Esto puede provocar: ejecución remota de código (RCE), escalada de privilegios locales, vulnerabilidad de todo el sistema, persistencia y puertas traseras. Esto se ha corregido en la versión 0.5.0b3.dev90."
    }
  ],
  "lastModified": "2026-06-17T09:39:31.443",
  "sourceIdentifier": "security-advisories@github.com"
}