PT-2026-60372 · Unknown · Cyberdrop-Dl-Patched
CVE-2026-54254
·
Published
2026-07-15
·
Updated
2026-07-23
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
cyberdrop-dl-patched versions prior to 9.14.0
Description
When processing Pixeldrain URLs, the software may send an
Authorization header containing the user's API key to unverified hosts. This occurs because the application matches URLs to a crawler if the host contains a supported host as a sub-string rather than an exact match. Consequently, a malicious domain that mimics a supported host can trigger the Pixeldrain crawler, causing the application to send API requests to the malicious host and leak the API key.Recommendations
Update to version 9.14.0.
Delete and regenerate any Pixeldrain API keys used with the software, as they should be considered compromised.
Fix
RCE
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cyberdrop-Dl-Patched