PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing, privilege escalation, and supply chain attacks. This issue has been patched in version 1.1.3.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pubnet Project
Pubnet Project pubnet |
|
| Vendors & Products |
Pubnet Project
Pubnet Project pubnet |
Sat, 29 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing, privilege escalation, and supply chain attacks. This issue has been patched in version 1.1.3. | |
| Title | PubNet Critical Authentication Bypass Allows Unauthenticated Package Upload and Identity Spoofing | |
| Weaknesses | CWE-306 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-01T19:15:10.692Z
Reserved: 2025-11-17T20:55:34.694Z
Link: CVE-2025-65112
No data.
Status : Awaiting Analysis
Published: 2025-11-29T01:16:02.467
Modified: 2025-12-01T15:39:33.110
Link: CVE-2025-65112
No data.