Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-75597— pyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo

Quick assessment

Affected
pyload pyload
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

pyLoad 是一款用 Python 编写的免费开源下载管理器。在版本 0.5.0b3.dev101 之前, 中的 路由会渲染 Jinja2 模板,且该路由未设置任何身份验证要求。虽然所有等效的直接路由(如 、 、 、 等)均通过 装饰器进行保护,但这些页面所对应的底层模板却可以通过上述 端点被未认证用户直接访问。 此外,在 中存在一个异常属性拼写错误(使用了 而非正确的 ),导致内部 Jinja2 变量名在返回给未认证用户的 HTTP 500 响应体中被泄露。攻击者还可以通过观察 HTTP 200 与 500 状

CVSS 5.3 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
pyload pyload < 0.5.0b3.dev101 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75597

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
pyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo
Source: CVE Program / CVE List V5
Vulnerability Description
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the `/web/<path:filename>` route in `src/pyload/webui/app/blueprints/app_blueprint.py` renders Jinja2 templates without any authentication requirement. Every equivalent direct route (`/logs`, `/settings`, `/queue`, `/dashboard`, etc.) is protected by `@login_required`, but the underlying templates for all of these pages are accessible unauthenticated via this endpoint. Combined with an exception attribute typo in `src/pyload/webui/app/handlers.py` (`exc.desc` instead of `exc.description`), internal Jinja2 variable names are leaked in HTTP 500 response bodies to unauthenticated callers. An attacker can also enumerate all valid template names by observing 200 vs 500 response differentiation. Version 0.5.0b3.dev101 contains a patch.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过错误消息导致的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
pyload pyload < 0.5.0b3.dev101 -

II. Public POCs for CVE-2026-75597

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75597

请登录查看更多情报信息。

Other References for CVE-2026-75597 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-75597

No comments yet


Leave a comment