Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames received from Telegram messages in the download_media method before using them in file path construction. When downloading media, if the user does not specify a custom filename (which is the common/default usage), the method falls back to using the file_name attribute from the media object. The attribute originates from Telegram's DocumentAttributeFilename and is controlled by the message sender. This issue is fixed in version 2.3.69.
History

Thu, 11 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Pyrofork Project
Pyrofork Project pyrofork
Vendors & Products Pyrofork Project
Pyrofork Project pyrofork

Thu, 11 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Dec 2025 02:00:00 +0000

Type Values Removed Values Added
Description Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames received from Telegram messages in the download_media method before using them in file path construction. When downloading media, if the user does not specify a custom filename (which is the common/default usage), the method falls back to using the file_name attribute from the media object. The attribute originates from Telegram's DocumentAttributeFilename and is controlled by the message sender. This issue is fixed in version 2.3.69.
Title Pyrofork has a Path Traversal in download_media Method
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-11T01:25:46.459Z

Updated: 2025-12-11T15:35:02.068Z

Reserved: 2025-12-10T18:46:14.762Z

Link: CVE-2025-67720

cve-icon Vulnrichment

Updated: 2025-12-11T15:34:53.708Z

cve-icon NVD

Status : Received

Published: 2025-12-11T02:16:19.090

Modified: 2025-12-11T02:16:19.090

Link: CVE-2025-67720

cve-icon Redhat

No data.