Directory Traversal in pyLoad Download Manager Affects Multiple Versions
CVE-2026-42315
8.1HIGH
What is CVE-2026-42315?
The vulnerability in pyLoad allows users with modify permissions to manipulate download locations by specifying arbitrary directories. This occurs due to a lack of sanitization when using the set_package_data() API function with the key '_folder'. Attackers could exploit this flaw prior to version 0.5.0b3.dev100, posing a significant risk to file system integrity and user data security. The issue has been addressed in subsequent releases.
Affected Version(s)
pyload < 0.5.0b3.dev100
