Path Traversal Vulnerability in pyLoad Download Manager
CVE-2026-42314

6.5MEDIUM

Key Information:

Vendor

Pyload

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-42314?

A path traversal vulnerability in pyLoad, a Python-based download manager, allows attackers to exploit insufficient sanitization of package folder names. The flawed string replacement mechanism allows the pattern ....// to be partially removed, leading to .. remaining in the path. This can be exploited during OS path resolution, potentially granting unauthorized access to sensitive file system areas. The issue has been addressed in version 0.5.0b3.dev100.

Affected Version(s)

pyload < 0.5.0b3.dev100

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.