Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2023-0297Code Injection in Pyload

CWE-94Code Injection11 documents10 sources
Severity
9.8CRITICALNVD
EPSS
94.0%
top 0.10%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 14
Latest updateJun 14

Description

Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5pyload/pyload_pyloadunspecified0.5.0b3.dev31
PyPIpyload-ng_project/pyload-ng< 0.5.0b3.dev31
NVDpyload/pyload0.4.20

Patches

🔴Vulnerability Details

4
OSV
Code Injection in pyload-ng2023-01-14
GHSA
Code Injection in pyload-ng2023-01-14
CVEList
Code Injection in pyload/pyload2023-01-14
VulnCheck
pyload pyload Improper Control of Generation of Code ('Code Injection')2023

💥Exploits & PoCs

3
Exploit-DB
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)2023-06-14
Nuclei
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
Metasploit
pyLoad js2py Python Execution

🕵️Threat Intelligence

1
Greynoiseio
NoiseLetter March 2025

📄Research Papers

2
CTF
easy / README
CTF
PC / README
CVE-2023-0297 — Code Injection in Pyload Pyload | cvebase