pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of jk parameter verification, the jk parameter input by the user is directly determined as dykpy.evaljs(), resulting in the server CPU being fully occupied and the web-ui becoming unresponsive. This vulnerability is fixed in 0.5.0b3.dev92.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 21 Aug 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of jk parameter verification, the jk parameter input by the user is directly determined as dykpy.evaljs(), resulting in the server CPU being fully occupied and the web-ui becoming unresponsive. This vulnerability is fixed in 0.5.0b3.dev92. | |
Title | Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs | |
Weaknesses | CWE-400 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-21T18:27:04.620Z
Updated: 2025-08-21T18:42:16.688Z
Reserved: 2025-08-19T15:16:22.916Z
Link: CVE-2025-57751

Updated: 2025-08-21T18:42:05.513Z

Status : Received
Published: 2025-08-21T19:15:43.227
Modified: 2025-08-21T19:15:43.227
Link: CVE-2025-57751

No data.