Path Traversal Vulnerability in pyLoad Download Manager
CVE-2026-42314
6.5MEDIUM
What is CVE-2026-42314?
A path traversal vulnerability in pyLoad, a Python-based download manager, allows attackers to exploit insufficient sanitization of package folder names. The flawed string replacement mechanism allows the pattern ....// to be partially removed, leading to .. remaining in the path. This can be exploited during OS path resolution, potentially granting unauthorized access to sensitive file system areas. The issue has been addressed in version 0.5.0b3.dev100.
Affected Version(s)
pyload < 0.5.0b3.dev100
