CVE-2025-55156

HIGH

pyLoad <0.5.0b3.dev91 - SQL Injection

Title source: llm
STIX 2.1

Description

pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to SQL Injection. Attackers can modify or delete data in the database, causing data errors or loss. This issue has been patched in version 0.5.0b3.dev91.

Scores

CVSS v4 7.8
EPSS 0.0005
EPSS Percentile 14.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (2)
pyload/pyload < 0.5.0b3.dev91
pypi/pyload-ng 0 - 0.5.0b3.dev91PyPI
Published Aug 11, 2025
Tracked Since Feb 18, 2026