Path Traversal Vulnerability in pyLoad Download Manager
CVE-2026-32808
8.1HIGH
What is CVE-2026-32808?
A path traversal vulnerability exists in pyLoad, a popular open-source download manager. This issue arises during the password verification process for certain encrypted 7z archives, where the software incorrectly derives file paths from untrusted input. This mismanagement allows attackers to manipulate the output, potentially leading to arbitrary file deletion outside the intended extraction directory. Users are advised to update to version 0.5.0b3.dev97 or later to mitigate this risk.
Affected Version(s)
pyload >= 0.4.9-6262-g2fa0b11d3, < 0.5.0b3.dev97
