Jinja2 Template Exposure in pyLoad Download Manager Software by pyLoad
CVE-2026-75597
5.3MEDIUM
What is CVE-2026-75597?
A security issue in pyLoad, a Python-based download manager, allows unauthorized access to Jinja2 templates through specific routes without authentication. The vulnerable endpoint permits access to internal information across various pages such as logs, settings, and dashboards. This lack of access control combined with an isolated exception handling error can result in the exposure of sensitive internal variables, potentially aiding attackers in enumerating valid template names based on server response variations. Users are advised to upgrade to version 0.5.0b3.dev101, which rectifies these vulnerabilities.
Affected Version(s)
pyload < 0.5.0b3.dev101
