Arbitrary Code Injection Affecting pyload-ng package, versions [,0.5.0b3.dev31)
Threat Intelligence
Exploit Maturity
Mature
EPSS
58.46% (98th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-PYLOADNG-3230895
- published 15 Jan 2023
- disclosed 15 Jan 2023
- credit bAu
Introduced: 15 Jan 2023
CVE-2023-0297 Open this link in a new tabHow to fix?
Upgrade pyload-ng
to version 0.5.0b3.dev31 or higher.
Overview
pyload-ng is a The free and open-source Download Manager written in pure Python
Affected versions of this package are vulnerable to Arbitrary Code Injection via the jk
parameter, which passes user input, potentially including arbitrary OS commands, to pyimport
.
References
CVSS Scores
version 3.1