{"id":"CVE-2026-54254","aliases":["PYSEC-2026-3460"],"url":"https://o3.security/vulnerability/CVE-2026-54254","summary":"Pixeldrain API key shared with unverified thirdparty sites","details":"### Summary\n\nWhen processing Pixeldrain URLs, `cyberdrop-dl-patched` could send an `Authorization` header that includes the user's API key to unverified hosts.\n\n### Details\n\nPixeldrain offers several alternative domains in case the user's ISP blocks the primary domain. To support this, requests made by `cyberdrop-dl-patched` are not hardcoded and will use the same host as the input URL for API requests.\n\n`cyberdrop-dl-patched` matches URLs to a crawler based on their host. If the host contains a crawler's supported host as a sub-string, it will match to that crawler. \n\nAn URL from a malicious domain (ex: `https://evil-pixeldrain.com`) would successfully match to the Pixeldrain crawler and `cyberdrop-dl-patched` will blindly use that host for any API request (`https://evil-pixeldrain.com/api`), leaking the user's API key to the malicious actor via the `Authorization` header.\n\n### Impact\nAnyone who has setup a Pixeldrain API key with `cyberdrop-dl-patched` and uses `cyberdrop-dl-patched` on sites that could spawn downloads for other sites (ex: forums, Wordpress, Pixeldrain itself, etc...)\n\n### Patches\n`cyberdrop-dl-patched`  v9.14.0 fixes this issue by rejecting any Pixedrain URL if the host does not match an official domain __exactly__.\n\n### Workarounds\nIt's recommended to upgrade `cyberdrop-dl-patched` to version v9.14.0\n\nAnyone who has used a Pixeldrain API key with `cyberdrop-dl-patched` should consider them compromised and delete them from their Pixeldrain account.","published":"2026-07-15T22:00:53Z","modified":"2026-07-23T15:11:45.835725135Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"cyberdrop-dl-patched","fixedVersion":"9.14.0"}],"fix":{"url":"https://github.com/Cyberdrop-DL/cyberdrop-dl/commit/4479555ae3f9d56d7657d6179a5bac3123eb4e2b","label":"Cyberdrop-DL/cyberdrop-dl@4479555"},"references":[{"type":"WEB","url":"https://github.com/Cyberdrop-DL/cyberdrop-dl/security/advisories/GHSA-f5pf-q7c7-m3vv"},{"type":"WEB","url":"https://github.com/Cyberdrop-DL/cyberdrop-dl/commit/4479555ae3f9d56d7657d6179a5bac3123eb4e2b"},{"type":"WEB","url":"https://docs.pixeldrain.com/questions_and_answers/#alternative-domain-names"},{"type":"PACKAGE","url":"https://github.com/Cyberdrop-DL/cyberdrop-dl"},{"type":"WEB","url":"https://github.com/Cyberdrop-DL/cyberdrop-dl/releases/tag/9.14.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-23T15:11:45.835725135Z"}}