CVE-2026-42315
EUVD-2026-2912311.05.2026, 18:16
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_folder", there is no sanitization at all, allowing a user with Perms.MODIFY to specify arbitrary directories as download locations for a package. This vulnerability is fixed in 0.5.0b3.dev100.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pyload-ng_project | pyload-ng | 𝑥 < 0.5.0b3.dev100 |
𝑥
= Vulnerable software versions