PT-2026-108987 · Pyload · Pyload

CVE-2026-75597

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions pyLoad versions prior to 0.5.0b3.dev101
Description The /web/<path:filename> endpoint in src/pyload/webui/app/blueprints/app blueprint.py renders Jinja2 templates without requiring authentication, bypassing the @login required protection applied to direct routes such as /logs, /settings, /queue, and /dashboard. Additionally, a typo in src/pyload/webui/app/handlers.py where exc.desc is used instead of exc.description causes the application to leak internal Jinja2 variable names in HTTP 500 response bodies. An attacker can also enumerate valid template names by analyzing the difference between 200 and 500 HTTP response codes.
Recommendations Update pyLoad to version 0.5.0b3.dev101 or later. As a temporary mitigation, restrict access to the /web/<path:filename> endpoint to prevent unauthenticated template rendering and information leakage.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75597
GHSA-J92P-C242-7HFX

Affected Products

Pyload