Executive brief
`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
Affected products
- PyPI pyload-ng
Junglewise Threat Intelligence
CVE-2025-54140 · Severity: low · CVSS 3.1 · Published 2026-07-07
Technologies: pyload-ng (PyPI). Vendors: PyPI.
`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write