Description
Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages
Scores
CVSS v4
8.7
EPSS
0.0037
EPSS Percentile
58.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-281
Status
published
Products (2)
Pyload/Pyload
< 0.5.0b3.dev77
pypi/pyload-ng
0PyPI
Published
Jul 08, 2025
Tracked Since
Feb 18, 2026