CVE-2025-67720 describes a path traversal vulnerability in Pyrofork versions 2.3.68 and earlier, an asynchronous MTProto API framework. The flaw occurs when the download_media method processes unsanitized filenames from Telegram messages, allowing a malicious sender to control the file path during media downloads if a custom filename is not specified. This vulnerability carries a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low complexity, requiring user interaction, to achieve high integrity impact (e.g., arbitrary file creation/overwrite) without affecting confidentiality or availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mayuri-Chan | Pyrofork | < 2.3.69CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.