CVE-2025-7346: pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
(updated )
Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages.
References
- github.com/advisories/GHSA-x698-5hjm-w2m5
- github.com/pyload/pyload/blob/4159a1191ec4fe6d927e57a9c4bb8f54e16c381d/src/pyload/webui/app/blueprints/cnl_blueprint.py
- github.com/pyload/pyload/blob/4159a1191ec4fe6d927e57a9c4bb8f54e16c381d/src/pyload/webui/app/blueprints/cnl_blueprint.py
- github.com/pyload/pyload/commit/f4e2d12416ba2dfac7b036d5c8d6dab5461b9840
- github.com/pyload/pyload/security/advisories/GHSA-x698-5hjm-w2m5
- nvd.nist.gov/vuln/detail/CVE-2025-7346
Code Behaviors & Features
Detect and mitigate CVE-2025-7346 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →