Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Pyload — Vulnerabilities & Security Advisories 37

Browse all 37 CVE security advisories affecting Pyload. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Pyload is an open-source download manager and automation tool designed to facilitate the collection of files from various hosting services. Its architecture, which often involves executing user-supplied scripts and managing complex file interactions, has historically exposed it to significant security risks. Analysis of its thirty-seven recorded Common Vulnerabilities and Exposures reveals a pattern of critical flaws, primarily involving Remote Code Execution (RCE) and Cross-Site Scripting (XSS). These vulnerabilities frequently stem from insufficient input validation and improper handling of uploaded content, allowing attackers to escalate privileges or inject malicious payloads. Notable incidents highlight the severity of these issues, with several CVEs enabling full system compromise through simple configuration changes or file uploads. The software’s reliance on Python-based execution engines further amplifies the risk, as many exploits leverage deserialization flaws or command injection vectors. Consequently, users must apply strict security hardening and regular updates to mitigate these persistent threats inherent in its design.

Top products by Pyload: pyload pyload/pyload
MediumGHSA-60hx-chf7-33322026-04-22
invalidate user session on user modify/delete/password change (fixes … · pyload/pyload@e95804f · GitHub
HighCVE-2026-41332026-04-22
Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass) · Advisory · pyload/pyload · GitHub
High2026-04-10
WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actions · Advisory · pyload/pyload · GitHub
HighGHSA-4744-96p5-mp2j2026-04-08
fix GHSA-4744-96p5-mp2j and GHSA-w48f-wwwf-f5fr security advisories · pyload/pyload@c4cf995 · GitHub
HighCVE-2026-354832026-04-08
Improper Neutralization of Special Elements used in an OS Command · Advisory · pyload/pyload · GitHub
HighGHSA-7q4m-8hv2-4qh32026-04-08
Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix Bypass · Advisory · pyload/pyload ·
HighCVE-2026-335092026-04-08
Incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask session store and co
HighGHSA-7gvf-3w72-p2pg2026-04-07
fix GHSA-7gvf-3w72-p2pg security advisory · pyload/pyload@33c55da · GitHub
HighCVE-2026-339922026-04-07
SSRF fix bypass via HTTP redirect: CVE-2026-33992 filter validates only initial URL, pycurl follows redirects to interna
HighCVE-2025-617732025-10-10
pyLoad CNL and captcha handlers allow code Injection via unsanitized parameters · Advisory · pyload/pyload · GitHub
HighCVE-2025-577512025-08-23
Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs · Advisory · pyload/pyload · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with Pyload. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.