Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

pyload — Vulnerabilities & Security Advisories 36

All 36 CVE vulnerabilities found in pyload, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations associated with the pyload web download manager developed by pyload-team. It compiles security findings related to input validation flaws, authentication bypasses, and other critical design or implementation defects that have been disclosed for this specific open-source application. The database covers vulnerabilities reported and tracked from 2014 through the present day, ensuring a comprehensive historical view of the software’s security posture as it evolved through various releases. Users can utilize this resource to track vendor advisories issued by the pyload-team, understand the prevalence and nature of specific weakness classes within the download manager ecosystem, and look up the complete vulnerability history of pyload to assess past risks. This aggregated data serves as a centralized reference point for security researchers, system administrators, and developers who need to evaluate the impact of known issues on their deployment environments. By presenting these findings in a unified structure, the page facilitates easier analysis of recurring security patterns and helps stakeholders make informed decisions regarding software upgrades, mitigation strategies, and compliance auditing. The information is derived from official security bulletins, community reports, and public vulnerability databases, providing a reliable foundation for understanding the security landscape surrounding pyload without requiring access to proprietary or internal scanning tools.

Vendor: pyload

CVE IDTitleCVSSSeverityPublished
CVE-2026-45306 pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory CWE-706 6.5 Medium2026-05-28
CVE-2026-45348 pyLoad: Stored XSS in Downloads view via unsanitized link URL in packages.js template literal CWE-79 8.7 High2026-05-28
CVE-2026-46561 pyLoad: SSRF via HTTP Redirect Bypass in parse_urls API CWE-918 5.0 Medium2026-05-28
CVE-2026-44226 pyLoad: Unauthenticated traceback disclosure via global exception handler in WebUI CWE-209 5.3 Medium2026-05-11
CVE-2026-42315 pyLoad: Path Traversal via Package Folder Name in set_package_data CWE-22 8.1 High2026-05-11
CVE-2026-42314 pyLoad: Path Traversal via Package Folder Name CWE-22 6.5 Medium2026-05-11
CVE-2026-42312 pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification CWE-295 6.8 Medium2026-05-11
CVE-2026-42313 pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy CWE-441 8.3 High2026-05-11
CVE-2026-41133 pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass) CWE-613 8.8 High2026-04-21
CVE-2026-40594 pyLoad: Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global State Race Condition) CWE-346 4.8 Medium2026-04-21
CVE-2026-40071 pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actions CWE-863 5.4 Medium2026-04-09
CVE-2026-35592 pyLoad has an Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix Bypass CWE-22 5.3 Medium2026-04-07
CVE-2026-35586 Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ng CWE-863 6.8 Medium2026-04-07
CVE-2026-35464 pyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask session store and code execution CWE-502 7.5 High2026-04-07
CVE-2026-35463 pyLoad has Improper Neutralization of Special Elements used in an OS Command CWE-78 8.8 High2026-04-07
CVE-2026-35459 pyLoad has SSRF fix bypass via HTTP redirect CWE-918 4.6AIMediumAI2026-04-06
CVE-2026-35187 pyLoad has SSRF in parse_urls API endpoint via unvalidated URL parameter CWE-918 7.7 High2026-04-06
CVE-2026-33992 pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration CWE-918 7.7 -2026-03-27
CVE-2026-33511 pyload-ng: Authentication Bypass via Host Header Injection in ClickNLoad CWE-639 8.2 -2026-03-24
CVE-2026-33509 pyload-ng: SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration CWE-269 7.5 High2026-03-24
CVE-2026-33314 pyload-ng: Improper Authentication and Origin Validation Error CWE-287 6.5 Medium2026-03-24
CVE-2026-32808 pyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password Verification CWE-22 8.1 High2026-03-20
CVE-2026-29778 pyLoad: Arbitrary File Write via Path Traversal in edit_package() CWE-23 7.1 High2026-03-07
CVE-2025-61773 pyLoad CNL and captcha handlers allow code Injection via unsanitized parameters CWE-74 8.1 High2025-10-09
CVE-2025-57751 Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs CWE-400 6.5AIMediumAI2025-08-21
CVE-2025-55156 PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter CWE-89 9.1AICriticalAI2025-08-11
CVE-2025-54802 pyLoad CNL Blueprint is vulnerable to Path Traversal through `dlc_path` leading to Remote Code Execution (RCE) CWE-22 9.8 Critical2025-08-05
CVE-2025-54140 pyLoad has Path Traversal Vulnerability in json/upload Endpoint that allows Arbitrary File Write CWE-22 7.5 High2025-07-22
CVE-2025-53890 pyLoad vulnerable to remote code execution through js2py onCaptchaResult CWE-94 9.8 Critical2025-07-14
CVE-2025-7346 pyLoad 安全漏洞 CWE-281 6.2AIMediumAI2025-07-08

All 36 known CVE vulnerabilities affecting pyload with full Chinese analysis, references, and POCs where available.