Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

pyload — Vulnerabilities & Security Advisories 45

Browse all 45 CVE security advisories affecting pyload. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Pyload is an open-source download manager and automation tool designed to facilitate the collection of files from various hosting services. Its architecture, which often involves executing user-supplied scripts and managing complex file interactions, has historically exposed it to significant security risks. Analysis of its thirty-seven recorded Common Vulnerabilities and Exposures reveals a pattern of critical flaws, primarily involving Remote Code Execution (RCE) and Cross-Site Scripting (XSS). These vulnerabilities frequently stem from insufficient input validation and improper handling of uploaded content, allowing attackers to escalate privileges or inject malicious payloads. Notable incidents highlight the severity of these issues, with several CVEs enabling full system compromise through simple configuration changes or file uploads. The software’s reliance on Python-based execution engines further amplifies the risk, as many exploits leverage deserialization flaws or command injection vectors. Consequently, users must apply strict security hardening and regular updates to mitigate these persistent threats inherent in its design.

Found 36 results / 45 Clear Filters
Top products by pyload: pyload pyload/pyload
CVE ID Title CVSS Severity Published
CVE-2026-45306 pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory — pyload CWE-706 6.5 Medium 2026-05-28
CVE-2026-45348 pyLoad: Stored XSS in Downloads view via unsanitized link URL in packages.js template literal — pyload CWE-79 8.7 High 2026-05-28
CVE-2026-46561 pyLoad: SSRF via HTTP Redirect Bypass in parse_urls API — pyload CWE-918 5.0 Medium 2026-05-28
CVE-2026-44226 pyLoad: Unauthenticated traceback disclosure via global exception handler in WebUI — pyload CWE-209 5.3 Medium 2026-05-11
CVE-2026-42315 pyLoad: Path Traversal via Package Folder Name in set_package_data — pyload CWE-22 8.1 High 2026-05-11
CVE-2026-42314 pyLoad: Path Traversal via Package Folder Name — pyload CWE-22 6.5 Medium 2026-05-11
CVE-2026-42312 pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification — pyload CWE-295 6.8 Medium 2026-05-11
CVE-2026-42313 pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy — pyload CWE-441 8.3 High 2026-05-11
CVE-2026-41133 pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass) — pyload CWE-613 8.8 High 2026-04-21
CVE-2026-40594 pyLoad: Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global State Race Condition) — pyload CWE-346 4.8 Medium 2026-04-21
CVE-2026-40071 pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actions — pyload CWE-863 5.4 Medium 2026-04-09
CVE-2026-35592 pyLoad has an Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix Bypass — pyload CWE-22 5.3 Medium 2026-04-07
CVE-2026-35586 Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ng — pyload CWE-863 6.8 Medium 2026-04-07
CVE-2026-35464 pyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask session store and code execution — pyload CWE-502 7.5 High 2026-04-07
CVE-2026-35463 pyLoad has Improper Neutralization of Special Elements used in an OS Command — pyload CWE-78 8.8 High 2026-04-07
CVE-2026-35459 pyLoad has SSRF fix bypass via HTTP redirect — pyload CWE-918 4.6AI Medium AI 2026-04-06
CVE-2026-35187 pyLoad has SSRF in parse_urls API endpoint via unvalidated URL parameter — pyload CWE-918 7.7 High 2026-04-06
CVE-2026-33992 pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration — pyload CWE-918 7.7 - 2026-03-27
CVE-2026-33511 pyload-ng: Authentication Bypass via Host Header Injection in ClickNLoad — pyload CWE-639 8.2 - 2026-03-24
CVE-2026-33509 pyload-ng: SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script Configuration — pyload CWE-269 7.5 High 2026-03-24
CVE-2026-33314 pyload-ng: Improper Authentication and Origin Validation Error — pyload CWE-287 6.5 Medium 2026-03-24
CVE-2026-32808 pyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password Verification — pyload CWE-22 8.1 High 2026-03-20
CVE-2026-29778 pyLoad: Arbitrary File Write via Path Traversal in edit_package() — pyload CWE-23 7.1 High 2026-03-07
CVE-2025-61773 pyLoad CNL and captcha handlers allow code Injection via unsanitized parameters — pyload CWE-74 8.1 High 2025-10-09
CVE-2025-57751 Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs — pyload CWE-400 6.5AI Medium AI 2025-08-21
CVE-2025-55156 PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter — pyload CWE-89 9.1AI Critical AI 2025-08-11
CVE-2025-54802 pyLoad CNL Blueprint is vulnerable to Path Traversal through `dlc_path` leading to Remote Code Execution (RCE) — pyload CWE-22 9.8 Critical 2025-08-05
CVE-2025-54140 pyLoad has Path Traversal Vulnerability in json/upload Endpoint that allows Arbitrary File Write — pyload CWE-22 7.5 High 2025-07-22
CVE-2025-53890 pyLoad vulnerable to remote code execution through js2py onCaptchaResult — pyload CWE-94 9.8 Critical 2025-07-14
CVE-2025-7346 pyLoad 安全漏洞 — Pyload CWE-281 6.2AI Medium AI 2025-07-08

This page lists every published CVE security advisory associated with pyload. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.