{"id":"CVE-2025-62611","aliases":["GHSA-r397-ff8c-wv2g","PYSEC-2026-1110"],"url":"https://o3.security/vulnerability/CVE-2025-62611","summary":"aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server","details":"aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings are not checked before sending local files to MySQL server, which allows obtaining arbitrary files from the client using a rogue server. It is possible to create a rogue MySQL server that emulates authorization, ignores client flags and requests arbitrary files from the client by sending a LOAD_LOCAL instruction packet. This issue has been patched in version 0.3.0.","published":"2025-10-22T19:29:26.708Z","modified":"2026-07-15T01:48:56.384319102Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"aiomysql","fixedVersion":"0.3.0"}],"fix":{"url":"https://github.com/aio-libs/aiomysql/commit/32c4520dae3711367ded74a4726dcb8bb8919538","label":"aio-libs/aiomysql@32c4520"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62611.json"},{"type":"ADVISORY","url":"https://github.com/aio-libs/aiomysql/security/advisories/GHSA-r397-ff8c-wv2g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62611"},{"type":"FIX","url":"https://github.com/aio-libs/aiomysql/commit/32c4520dae3711367ded74a4726dcb8bb8919538"},{"type":"FIX","url":"https://github.com/aio-libs/aiomysql/pull/1044"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:56.384319102Z"}}