{"id":"GHSA-f5pf-q7c7-m3vv","summary":"Pixeldrain API key shared with unverified thirdparty sites","details":"### Summary\n\nWhen processing Pixeldrain URLs, `cyberdrop-dl-patched` could send an `Authorization` header that includes the user's API key to unverified hosts.\n\n### Details\n\nPixeldrain offers several alternative domains in case the user's ISP blocks the primary domain. To support this, requests made by `cyberdrop-dl-patched` are not hardcoded and will use the same host as the input URL for API requests.\n\n`cyberdrop-dl-patched` matches URLs to a crawler based on their host. If the host contains a crawler's supported host as a sub-string, it will match to that crawler. \n\nAn URL from a malicious domain (ex: `https://evil-pixeldrain.com`) would successfully match to the Pixeldrain crawler and `cyberdrop-dl-patched` will blindly use that host for any API request (`https://evil-pixeldrain.com/api`), leaking the user's API key to the malicious actor via the `Authorization` header.\n\n### Impact\nAnyone who has setup a Pixeldrain API key with `cyberdrop-dl-patched` and uses `cyberdrop-dl-patched` on sites that could spawn downloads for other sites (ex: forums, Wordpress, Pixeldrain itself, etc...)\n\n### Patches\n`cyberdrop-dl-patched`  v9.14.0 fixes this issue by rejecting any Pixedrain URL if the host does not match an official domain __exactly__.\n\n### Workarounds\nIt's recommended to upgrade `cyberdrop-dl-patched` to version v9.14.0\n\nAnyone who has used a Pixeldrain API key with `cyberdrop-dl-patched` should consider them compromised and delete them from their Pixeldrain account.","aliases":["CVE-2026-54254","PYSEC-2026-3460"],"modified":"2026-07-23T15:11:45.835725135Z","published":"2026-07-15T22:00:53Z","database_specific":{"github_reviewed_at":"2026-07-15T22:00:53Z","nvd_published_at":null,"cwe_ids":["CWE-20","CWE-200"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/Cyberdrop-DL/cyberdrop-dl/security/advisories/GHSA-f5pf-q7c7-m3vv"},{"type":"WEB","url":"https://github.com/Cyberdrop-DL/cyberdrop-dl/commit/4479555ae3f9d56d7657d6179a5bac3123eb4e2b"},{"type":"WEB","url":"https://docs.pixeldrain.com/questions_and_answers/#alternative-domain-names"},{"type":"PACKAGE","url":"https://github.com/Cyberdrop-DL/cyberdrop-dl"},{"type":"WEB","url":"https://github.com/Cyberdrop-DL/cyberdrop-dl/releases/tag/9.14.0"}],"affected":[{"package":{"name":"cyberdrop-dl-patched","ecosystem":"PyPI","purl":"pkg:pypi/cyberdrop-dl-patched"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.5.0"},{"fixed":"9.14.0"}]}],"versions":["8.10.0","8.5.0","8.6.0","8.7.0","8.8.0","8.9.0","9.10.0","9.10.1","9.10.2","9.10.3","9.11.0","9.12.0","9.13.0","9.13.0.dev0","9.3.1","9.3.1.dev0","9.4.0","9.4.1","9.4.2","9.4.3","9.5.0","9.5.1","9.6.0","9.7.0","9.7.1.dev0","9.7.1.dev1","9.7.1.dev2","9.8.0","9.8.1","9.9.0","9.9.1.dev0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-f5pf-q7c7-m3vv/GHSA-f5pf-q7c7-m3vv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}