PT-2026-60372 · Unknown · Cyberdrop-Dl-Patched

CVE-2026-54254

·

Published

2026-07-15

·

Updated

2026-07-23

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions cyberdrop-dl-patched versions prior to 9.14.0
Description When processing Pixeldrain URLs, the software may send an Authorization header containing the user's API key to unverified hosts. This occurs because the application matches URLs to a crawler if the host contains a supported host as a sub-string rather than an exact match. Consequently, a malicious domain that mimics a supported host can trigger the Pixeldrain crawler, causing the application to send API requests to the malicious host and leak the API key.
Recommendations Update to version 9.14.0. Delete and regenerate any Pixeldrain API keys used with the software, as they should be considered compromised.

Fix

RCE

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54254
GHSA-F5PF-Q7C7-M3VV
PYSEC-2026-3460

Affected Products

Cyberdrop-Dl-Patched