PT-2026-108987 · Pyload · Pyload
CVE-2026-75597
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
pyLoad versions prior to 0.5.0b3.dev101
Description
The
/web/<path:filename> endpoint in src/pyload/webui/app/blueprints/app blueprint.py renders Jinja2 templates without requiring authentication, bypassing the @login required protection applied to direct routes such as /logs, /settings, /queue, and /dashboard. Additionally, a typo in src/pyload/webui/app/handlers.py where exc.desc is used instead of exc.description causes the application to leak internal Jinja2 variable names in HTTP 500 response bodies. An attacker can also enumerate valid template names by analyzing the difference between 200 and 500 HTTP response codes.Recommendations
Update pyLoad to version 0.5.0b3.dev101 or later.
As a temporary mitigation, restrict access to the
/web/<path:filename> endpoint to prevent unauthenticated template rendering and information leakage.Exploit
Fix
Generation of Error Message Containing Sensitive Information
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pyload