PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing, privilege escalation, and supply chain attacks. This issue has been patched in version 1.1.3.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Dec 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ricardoboss
Ricardoboss pubnet |
|
| CPEs | cpe:2.3:a:ricardoboss:pubnet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ricardoboss
Ricardoboss pubnet |
Mon, 01 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pubnet Project
Pubnet Project pubnet |
|
| Vendors & Products |
Pubnet Project
Pubnet Project pubnet |
Sat, 29 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing, privilege escalation, and supply chain attacks. This issue has been patched in version 1.1.3. | |
| Title | PubNet Critical Authentication Bypass Allows Unauthenticated Package Upload and Identity Spoofing | |
| Weaknesses | CWE-306 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-11-29T00:38:41.672Z
Updated: 2025-12-01T19:15:10.692Z
Reserved: 2025-11-17T20:55:34.694Z
Link: CVE-2025-65112
Updated: 2025-12-01T18:47:45.511Z
Status : Analyzed
Published: 2025-11-29T01:16:02.467
Modified: 2025-12-03T21:51:39.093
Link: CVE-2025-65112
No data.