pyload-ng
PyPI37 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting pyload-ngpage 1 of 1
- CVE-2023-0055MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.5.0b3.dev322023-01-04
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev31 (47 versions)
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository pyload/pyload prior to 0.5.0b3.dev32.
- CVE-2023-0057MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.5.0b3.dev332023-01-05
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev32 (48 versions)
Improper Restriction of Rendered UI Layers or Frames in GitHub repository pyload/pyload prior to 0.5.0b3.dev33.
- CVE-2023-0227MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.5.0b3.dev362023-01-12
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev35 (51 versions)
Insufficient Session Expiration in GitHub repository pyload/pyload prior to 0.5.0b3.dev36.
- CVE-2023-0297CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.5.0b3.dev312023-01-14
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev30 (46 versions)
Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.
- CVE-2023-0434HIGHCVSS 7.5EG 7.5✓ Fixed in 0.5.0b3.dev402023-01-22
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev39 (53 versions)
Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40.
- CVE-2023-0435CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.5.0b3.dev412023-01-22
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev40 (54 versions)
Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41.
- CVE-2023-0488MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.5.0b3.dev422023-01-26
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev41 (55 versions)
Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.
- CVE-2023-0509HIGHCVSS 7.4EG 7.4✓ Fixed in 0.5.0b3.dev442023-01-26
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev43 (57 versions)
Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev44.
- CVE-2023-47890HIGHCVSS 8.8EG 8.8✓ Fixed in 0.5.0b3.dev752024-01-08
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev74 (82 versions)
pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.
- CVE-2024-1240MEDIUMCVSS 6.1EG 4.6✓ Fixed in fe94451dcc2be90b3889e2fd9d07b483c8a6dccd2024-11-15
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev93 (98 versions)
An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to mali…
- CVE-2024-21644HIGHCVSS 7.5EG 9.0✓ Fixed in 0.5.0b3.dev772024-01-08
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev76 (84 versions)
pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0…
- CVE-2024-21645MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.5.0b3.dev772024-01-08
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev76 (84 versions)
pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any unauthenticated actor to inject arbitrary messages into the logs gathered by `pyload`. Forged…
- CVE-2024-22416CRITICALCVSS 9.6EG 9.6✓ Fixed in 0.5.0b3.dev782024-01-18
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev77 (85 versions)
pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. Since the session cookie is not set to `SameSite: strict`, this opens the library up to severe at…
- CVE-2024-24808MEDIUMCVSS 4.7EG 4.7✓ Fixed in 0.5.0b3.dev792024-02-06
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev78 (86 versions)
pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values when redirecting users after login. pyLoad is validating URLs via the `get_redirect_url` …
- CVE-2024-32880CRITICALCVSS 9.1EG 9.12024-04-26
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev82 (90 versions)
pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution. There is no fix available at the ti…
- CVE-2024-39205CRITICALCVSS 9.8EG 9.82024-10-28
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev85 (91 versions)
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.
- CVE-2024-47821CRITICALCVSS 9.1EG 9.12024-10-25
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev99 (105 versions)
pyLoad is a free and open-source Download Manager. The folder `/.pyload/scripts` has scripts which are run when certain actions are completed, for e.g. a download is finished. By downloading a executable file to a folder in /scripts and pe…
- CVE-2025-53890CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.202025-07-15
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev89 (94 versions)
pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code allows unauthenticated remote attackers to execute arbitrary code in the client browser a…
- CVE-2025-54140HIGHCVSS 7.5EG 7.5✓ Fixed in 0.5.0b3.dev902025-07-22
vulnerable: 0.5.0b3.dev89
pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated path traversal vulnerability exists in the /json/upload endpoint of pyLoad. By manipulating the filename of an uploaded fi…
- CVE-2025-55156HIGHCVSS 7.8EG 0.0✓ Fixed in 0.5.0b3.dev912025-08-11
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev90 (95 versions)
pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to SQL Injection. Attackers can modify or delete data in the databas…
- CVE-2025-57751HIGHCVSS 7.7EG 0.0✓ Fixed in 0.5.0b3.dev922025-08-21
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev91 (96 versions)
pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of jk parameter verification, the jk parameter input by the user is directly determined as dy…
- CVE-2025-61773HIGHCVSS 8.1EG 8.1✓ Fixed in 0.5.0b3.dev912025-10-09
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev90 (95 versions)
pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient input validation in both the Captcha script endpoint and the Click'N'Load (CNL) Blueprint.…
- CVE-2025-7346HIGHCVSS 8.7EG 7.52025-07-08
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev88 (93 versions)
Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages
- CVE-2026-35187HIGHCVSS 7.7EG 7.72026-04-06
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev96 (101 versions)
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API function in src/pyload/core/api/__init__.py fetches arbitrary URLs server-side via get_url(url) (pycurl) without any URL …
- CVE-2026-35459CRITICALCVSS 9.1EG 9.12026-04-06
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev96 (101 versions)
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP validation to BaseDownloader.download() t…
- CVE-2026-35463HIGHCVSS 8.8EG 8.82026-04-07
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev96 (101 versions)
pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credential…
- CVE-2026-35464HIGHCVSS 7.5EG 7.52026-04-07
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev97 (102 versions)
pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-critical config options. The storage_folder option is not in t…
- CVE-2026-35586MEDIUMCVSS 6.8EG 6.8✓ Fixed in 0.5.0b3.dev972026-04-07
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev96 (101 versions)
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_config_value() uses incorrect option names ssl_cert and ssl_key, while the actual configurati…
- CVE-2026-35592MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.5.0b3.dev972026-04-07
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev96 (101 versions)
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() function in src/pyload/plugins/extractors/UnTar.py uses os.path.commonprefix() for its path traversal check, which performs…
- CVE-2026-40071MEDIUMCVSS 5.4EG 5.42026-04-09
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev97 (102 versions)
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /json/link_order, and /json/abort_link WebUI JSON endpoints enforce weaker permissions than the core API methods they inv…
- CVE-2026-40594MEDIUMCVSS 4.8EG 4.8✓ Fixed in 0.5.0b3.dev692026-04-21
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev68 (76 versions)
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secure before_request handler in src/pyload/webui/app/__init__.py reads the X-Forwarded-Proto header from any HTTP request …
- CVE-2026-41133HIGHCVSS 8.8EG 8.82026-04-22
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev97 (102 versions)
pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after…
- CVE-2026-42312MEDIUMCVSS 6.8EG 6.8✓ Fixed in 0.5.0b3.dev1002026-05-11
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev99 (104 versions)
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand…
- CVE-2026-42313HIGHCVSS 8.3EG 8.3✓ Fixed in 0.5.0b3.dev1002026-05-11
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev99 (104 versions)
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand…
- CVE-2026-42314MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.5.0b3.dev1002026-05-11
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev99 (104 versions)
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ after replacement (partial removal), lea…
- CVE-2026-42315HIGHCVSS 8.1EG 8.1✓ Fixed in 0.5.0b3.dev1002026-05-11
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev99 (104 versions)
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_folder", there is no sanitization at all…
- CVE-2026-44226MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.5.0b3.dev1002026-05-11
vulnerable: 0.5.0a5.dev528 ... 0.5.0b3.dev99 (104 versions)
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details to clients on unhandled exceptions. Because /web/<path:filename> is reachable without authe…
Check whether pyload-ng is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for pyload-ng CVEs against the assets you own.
Start Free Scan →