PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing, privilege escalation, and supply chain attacks. This issue has been patched in version 1.1.3.
History

Mon, 01 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Pubnet Project
Pubnet Project pubnet
Vendors & Products Pubnet Project
Pubnet Project pubnet

Sat, 29 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
Description PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing, privilege escalation, and supply chain attacks. This issue has been patched in version 1.1.3.
Title PubNet Critical Authentication Bypass Allows Unauthenticated Package Upload and Identity Spoofing
Weaknesses CWE-306
CWE-862
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-29T00:38:41.672Z

Updated: 2025-11-29T00:38:41.672Z

Reserved: 2025-11-17T20:55:34.694Z

Link: CVE-2025-65112

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-29T01:16:02.467

Modified: 2025-12-01T15:39:33.110

Link: CVE-2025-65112

cve-icon Redhat

No data.