Jinja2 Template Exposure in pyLoad Download Manager Software by pyLoad
CVE-2026-75597

5.3MEDIUM

Key Information:

Vendor

Pyload

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-75597?

A security issue in pyLoad, a Python-based download manager, allows unauthorized access to Jinja2 templates through specific routes without authentication. The vulnerable endpoint permits access to internal information across various pages such as logs, settings, and dashboards. This lack of access control combined with an isolated exception handling error can result in the exposure of sensitive internal variables, potentially aiding attackers in enumerating valid template names based on server response variations. Users are advised to upgrade to version 0.5.0b3.dev101, which rectifies these vulnerabilities.

Affected Version(s)

pyload < 0.5.0b3.dev101

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.