CVE-2025-62611
aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings are not checked before sending local files to MySQL server, which allows obtaining arbitrary files from the client using a rogue server. It is possible to create a rogue MySQL server that emulates authorization, ignores client flags and requests arbitrary files from the client by sending a LOAD_LOCAL instruction packet. This issue has been patched in version 0.3.0.
- Fix
- Available
- CVSS 4.0
- 8.2 HIGH
- EPSS
- 0.4% (29th percentile)
- Weakness
- CWE-73
- NVD status
- Deferred
- Published
- 2025-10-22
CVE-2025-62611 at NVD
No indexed exploits for CVE-2025-62611 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-62611 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.