VAITP Dataset

← Back to the dataset

CVE-2025-57751

Unverified `jk` parameter in pyLoad's CNL Blueprint causes Denial of Service.

  • CVSS 7.7
  • CWE-400
  • Resource Management
  • Remote

pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of jk parameter verification, the jk parameter input by the user is directly determined as dykpy.evaljs(), resulting in the server CPU being fully occupied and the web-ui becoming unresponsive. This vulnerability is fixed in 0.5.0b3.dev92.

CVSS base score
7.7
Published
2025-08-21
OWASP
A03 Injection
Orthogonal defect classification
Checking
Code defect classification
Missing Check
Category
Resource Management
Subcategory
Resource Exhaustion
Accessibility scope
Remote
Impact
Denial of Service (DoS)
Affected component
pyLoad
Fixed by upgrading
Yes

Solution

Upgrade pyLoad to version 0.5.0b3.dev92 or later.

Vulnerable code sample

from flask import Flask, request, jsonify
import execjs

app = Flask(__name__)

# This class and its method simulate the vulnerable component described in the CVE.
# It directly executes JavaScript provided by the user.
class DykPy:
    def evaljs(self, js_code):
        """
        Evaluates a string of JavaScript code without any validation or sandboxing.
        """
        try:
            # A malicious payload like 'function f(){while(true){}}'
            # will cause this call to hang indefinitely, consuming 100% CPU.
            context = execjs.compile(f"var result = ({js_code})();")
            return context.eval('result')
        except Exception as e:
            return f"JavaScript execution failed: {str(e)}"

dykpy = DykPy()

# This route simulates the "CNL Blueprint" endpoint mentioned in the CVE.
@app.route('/cnl', methods=['GET'])
def handle_cnl():
    # The 'jk' parameter is taken directly from the user's request.
    jk_parameter = request.args.get('jk')

    if not jk_parameter:
        return jsonify({"error": "jk parameter is required"}), 400

    # --- VULNERABILITY ---
    # The user-controlled 'jk' parameter is passed to the evaljs function
    # without any verification or sanitization. This allows an attacker to
    # execute arbitrary JavaScript on the server. A payload designed to consume
    # resources, such as an infinite loop, will cause a Denial of Service.
    result = dykpy.evaljs(jk_parameter)
    # --- END VULNERABILITY ---

    # If a malicious payload is used, the server will hang on the line above
    # and will never send this response.
    return jsonify({"status": "processed", "result": str(result)})

if __name__ == '__main__':
    # To trigger the vulnerability:
    # 1. Run this script.
    # 2. Make a request to:
    #    http://127.0.0.1:5000/cnl?jk=function(){while(true){}}
    # 3. The server's CPU usage will spike, and it will become unresponsive.
    app.run(host='0.0.0.0', port=5000)

Patched code sample

import re
from flask import abort, request
from dukpy import JSRuntimeError, dukpy

# The following function is a representation of the fixed code
# from pyLoad's 'module/web/blueprints/cnl.py'.
# The vulnerability CVE-2023-5751 (referenced as CVE-2025-57751 in the prompt)
# was fixed by adding a sanitization check for the 'jk' parameter before it is
# evaluated as JavaScript.

def flash():
    """
    This function handles the /flash endpoint for Click'N'Load.
    The added code block demonstrates the fix for the DoS vulnerability.
    In a real Flask application, 'request' is available from the application context.
    """
    jk = request.form.get("jk")
    crypted = request.form.get("crypted")

    if jk:
        # --- START OF THE VULNERABILITY FIX ---
        # Sanitize the 'jk' parameter to prevent arbitrary JavaScript execution.
        # The regex ensures that the user-provided string is a simple 'return'
        # statement, which is the expected format. It rejects loops (e.g., 'while(true){}')
        # or other complex code that could cause a Denial of Service by consuming all CPU.
        if not re.fullmatch(r"return\s+([0-9A-Za-z'\"_\+\-]+(\s*\.\s*[0-9A-Za-z'\"_\+\-]+)*);?", jk):
            # If the parameter does not match the safe pattern, abort the request.
            abort(400)
        # --- END OF THE VULNERABILITY FIX ---

        try:
            # After validation, the sanitized 'jk' parameter is considered safe to be
            # embedded into the JavaScript code block for evaluation by dukpy.
            crypted = dukpy.evaljs(
                f"var jk = function() {{{jk}}};f('{crypted}')")

        except JSRuntimeError as e:
            # Handle potential JavaScript errors gracefully.
            # The original code includes specific error handling logic.
            print(f"JSRuntimeError: {e}")
            pass

    # The rest of the function logic would continue here...
    # For demonstration, we assume it returns the processed 'crypted' data.
    return crypted

Payload

while(true){}

Cite this entry

@misc{vaitp:cve202557751,
  title        = {{Unverified `jk` parameter in pyLoad's CNL Blueprint causes Denial of Service.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2025},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2025-57751},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2025-57751/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::