CVE-2025-7346

HIGH

Application - Auth Bypass

Title source: llm
STIX 2.1

Description

Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages

Scores

CVSS v4 8.7
EPSS 0.0037
EPSS Percentile 58.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-281
Status published
Products (2)
Pyload/Pyload < 0.5.0b3.dev77
pypi/pyload-ng 0PyPI
Published Jul 08, 2025
Tracked Since Feb 18, 2026