{"id":"CVE-2025-67720","aliases":["GHSA-6h2f-wjhf-4wjx","PYSEC-2026-1841"],"url":"https://o3.security/vulnerability/CVE-2025-67720","summary":"Pyrofork has a Path Traversal in download_media Method","details":"Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames received from Telegram messages in the download_media method before using them in file path construction. When downloading media, if the user does not specify a custom filename (which is the common/default usage), the method falls back to using the file_name attribute from the media object. The attribute originates from Telegram's DocumentAttributeFilename and is controlled by the message sender. This issue is fixed in version 2.3.69.","published":"2025-12-11T01:25:46.459Z","modified":"2026-07-15T01:49:16.463615488Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pyrofork","fixedVersion":"2.3.69"}],"fix":{"url":"https://github.com/Mayuri-Chan/pyrofork/commit/2f2d515575cc9c360bd74340a61a1d2b1e1f1f95","label":"Mayuri-Chan/pyrofork@2f2d515"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/67xxx/CVE-2025-67720.json"},{"type":"ADVISORY","url":"https://github.com/Mayuri-Chan/pyrofork/security/advisories/GHSA-6h2f-wjhf-4wjx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67720"},{"type":"FIX","url":"https://github.com/Mayuri-Chan/pyrofork/commit/2f2d515575cc9c360bd74340a61a1d2b1e1f1f95"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:16.463615488Z"}}