External risk intelligence

PubNet Unauthenticated Package Upload and Identity Spoofing

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-65112

PubNet is a self-hosted package service. Such services are typically deployed as centralized, internet-facing or network-accessible repositories to facilitate collaboration and dependency management for developers across different environments, making the API endpoints commonly reachable in a deployment context.

Missing Authentication

Ricardoboss Pubnet

before 1.1.4

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in PubNet, a self-hosted package service, allowing unauthenticated attackers to impersonate any user and upload malicious packages. This could lead to significant risks such as identity spoofing, unauthorized privilege escalation, and supply chain attacks impacting software integrity.

  • Attackers can upload fake packages.
  • It allows impersonation and malicious code injection.
  • Confirm relevance and assess exposure to this risk.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can impersonate any user on a self-hosted PubNet service by uploading malicious packages. This vulnerability allows an attacker to submit packages with a forged author ID, potentially leading to the injection of compromised code into the software supply chain.

  • Unauthenticated network access required.
  • Uploading packages via the API triggers the vulnerability.
  • Risk of supply chain attacks and code compromise.

Live Threat

Current exploitation, exposure, and threat context

A critical vulnerability in PubNet's package upload endpoint could allow unauthenticated attackers to impersonate any user, potentially leading to the introduction of malicious code into the software supply chain. This could affect the integrity of published packages and the security of downstream projects relying on them.

  • Package integrity and authenticity.
  • Unauthenticated uploads to an arbitrary author.
  • Supply chain compromise and code injection.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in PubNet, a self-hosted package service, allows unauthenticated users to upload packages as any user by exploiting the `/api/storage/upload` endpoint. This could lead to identity spoofing, privilege escalation, and supply chain attacks. Identifying all instances of PubNet, confirming their reachability and criticality, and then coordinating with the accountable owners for remediation is the immediate priority.

  • Own the risk and remediation process.
  • Verify affected PubNet instances.
  • Plan and execute upgrades.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PubNet?

PubNet is a self-hosted repository service designed for Dart and Flutter developers. It acts as a private, centralized hub where teams store and manage software packages, allowing developers to share code dependencies across their various projects and build environments.

How does CVE-2025-65112 enable identity spoofing?

This vulnerability involves Missing Authentication for Critical Function (CWE-306) and Missing Authorization (CWE-862). Because the system fails to verify who is sending data to the storage endpoint, an attacker can supply an arbitrary author ID to masquerade as any legitimate user and inject packages into the repository.

When does the /api/storage/upload endpoint trigger this flaw?

The vulnerability is triggered whenever an unauthenticated request is sent to the package upload endpoint. It does not require any specific server-side configuration or prior account compromise; if the service is reachable, the lack of identity checks allows the malicious upload to proceed immediately.

Why is this CVE high-risk for my environment?

According to Halo Surface Signal, PubNet instances are typically deployed as network-accessible or internet-facing repositories to support developer collaboration. This deployment pattern increases the likelihood that attackers can reach the vulnerable API endpoint remotely to compromise your supply chain.

Do I need to update PubNet to fix this issue?

Yes, you should update to version 1.1.3 or later as soon as possible. Since this flaw allows unauthenticated attackers to manipulate the integrity of your code repository, applying the patch is the only way to enforce proper identity verification and stop unauthorized package uploads.

References