{"id":"PYSEC-2026-3460","summary":"Pixeldrain API key shared with unverified thirdparty sites","details":"### Summary\n\nWhen processing Pixeldrain URLs, `cyberdrop-dl-patched` could send an `Authorization` header that includes the user's API key to unverified hosts.\n\n### Details\n\nPixeldrain offers several alternative domains in case the user's ISP blocks the primary domain. To support this, requests made by `cyberdrop-dl-patched` are not hardcoded and will use the same host as the input URL for API requests.\n\n`cyberdrop-dl-patched` matches URLs to a crawler based on their host. If the host contains a crawler's supported host as a sub-string, it will match to that crawler. \n\nAn URL from a malicious domain (ex: `https://evil-pixeldrain.com`) would successfully match to the Pixeldrain crawler and `cyberdrop-dl-patched` will blindly use that host for any API request (`https://evil-pixeldrain.com/api`), leaking the user's API key to the malicious actor via the `Authorization` header.\n\n### Impact\nAnyone who has setup a Pixeldrain API key with `cyberdrop-dl-patched` and uses `cyberdrop-dl-patched` on sites that could spawn downloads for other sites (ex: forums, Wordpress, Pixeldrain itself, etc...)\n\n### Patches\n`cyberdrop-dl-patched`  v9.14.0 fixes this issue by rejecting any Pixedrain URL if the host does not match an official domain __exactly__.\n\n### Workarounds\nIt's recommended to upgrade `cyberdrop-dl-patched` to version v9.14.0\n\nAnyone who has used a Pixeldrain API key with `cyberdrop-dl-patched` should consider them compromised and delete them from their Pixeldrain account.","aliases":["CVE-2026-54254","GHSA-f5pf-q7c7-m3vv"],"modified":"2026-07-23T15:00:10.910036474Z","published":"2026-07-23T11:41:45.803654Z","references":[{"type":"WEB","url":"https://github.com/Cyberdrop-DL/cyberdrop-dl/security/advisories/GHSA-f5pf-q7c7-m3vv"},{"type":"WEB","url":"https://github.com/Cyberdrop-DL/cyberdrop-dl/commit/4479555ae3f9d56d7657d6179a5bac3123eb4e2b"},{"type":"WEB","url":"https://docs.pixeldrain.com/questions_and_answers/#alternative-domain-names"},{"type":"PACKAGE","url":"https://github.com/Cyberdrop-DL/cyberdrop-dl"},{"type":"WEB","url":"https://github.com/Cyberdrop-DL/cyberdrop-dl/releases/tag/9.14.0"},{"type":"PACKAGE","url":"https://pypi.org/project/cyberdrop-dl-patched"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f5pf-q7c7-m3vv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54254"}],"affected":[{"package":{"name":"cyberdrop-dl-patched","ecosystem":"PyPI","purl":"pkg:pypi/cyberdrop-dl-patched"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.5.0"},{"fixed":"9.14.0"}]}],"versions":["8.10.0","8.5.0","8.6.0","8.7.0","8.8.0","8.9.0","9.10.0","9.10.1","9.10.2","9.10.3","9.11.0","9.12.0","9.13.0","9.13.0.dev0","9.3.1","9.3.1.dev0","9.4.0","9.4.1","9.4.2","9.4.3","9.5.0","9.5.1","9.6.0","9.7.0","9.7.1.dev0","9.7.1.dev1","9.7.1.dev2","9.8.0","9.8.1","9.9.0","9.9.1.dev0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/cyberdrop-dl-patched/PYSEC-2026-3460.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}