PT-2025-48350 · Pubnet · Pubnet

CVE-2025-65112

·

Published

2025-11-29

·

Updated

2025-12-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PubNet versions prior to 1.1.3
Description PubNet is a self-hosted Dart & Flutter package service. The /api/storage/upload endpoint allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing, privilege escalation, and supply chain attacks. The issue allows attackers to forge any author-id, creating a perfect supply chain attack scenario.
Recommendations Versions prior to 1.1.3 should be updated to version 1.1.3 or later.

Exploit

Fix

LPE

Missing Authentication

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65112
GHSA-PG82-FQRG-Q6J5

Affected Products

Pubnet