---
id: CVE-2025-11607
title: A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6
summary: >-
  A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The
  impacted element is the function upload_music of the file
  app/controllers/v1/music.py of the component API Endpoint. Executing a
  manipulation of the argument …
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-22
vendor: harry0703
product: moneyprinterturbo
affected:
  - moneyprinterturbo <= 1.2.6
published: '2025-10-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11607'
references:
  - url: 'https://vuldb.com/?ctiid.327929'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327929'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.672550'
    label: cna@vuldb.com
  - url: >-
      https://www.notion.so/Arbitrary-File-Write-Vulnerability-in-MoneyPrinterTurbo-1-2-6-288014c4d9ca809bb411e4fe875d1e22
    label: cna@vuldb.com
  - url: >-
      https://www.notion.so/Arbitrary-File-Write-Vulnerability-in-MoneyPrinterTurbo-1-2-6-288014c4d9ca809bb411e4fe875d1e22
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0045
epssPercentile: 0.3708
ingestedAt: '2026-10-08T13:42:55.112Z'
---

## Overview

A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controllers/v1/music.py of the component API Endpoint. Executing a manipulation of the argument File can lead to path traversal. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

## Affected

- `moneyprinterturbo <= 1.2.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
