
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29778 is a relative path traversal vulnerability in the edit_package() function of pyload-ng, an open-source download manager written in Python. It allows authenticated users with MODIFY permission to write files to arbitrary locations on the filesystem outside the intended storage directory. The vulnerability affects pyload-ng versions >= 0.5.0b3.dev13 and <= 0.5.0b3.dev96, and was disclosed on March 4, 2026, with a patch released in version 0.5.0b3.dev97. The GitHub Advisory Database assigns a CVSS v3.1 score of 7.1 (High), while Feedly reports a base score of 6.5 (Medium) (GitHub Advisory, pyload Advisory).
The root cause is classified as CWE-23 (Relative Path Traversal): the edit_package() function sanitizes the pack_folder parameter using a single-pass string replacement that removes occurrences of ../, but does not iterate or canonicalize the result. An attacker can bypass this protection by submitting a crafted recursive traversal sequence such as pack_folder=..././..././..././tmp; after the single-pass replacement strips the embedded ../ fragments, the remaining string resolves to ../../../tmp, effectively escaping the intended storage directory. The attack vector is network-based, requires low privileges (an authenticated account with MODIFY permission), and no user interaction (GitHub Advisory, pyload Advisory).
Successful exploitation allows an authenticated attacker to write files to arbitrary locations on the server filesystem, such as /tmp or other system directories, outside the intended pyload storage path. This arbitrary file write primitive can be chained to achieve remote code execution — for example, by overwriting configuration files, cron jobs, or placing web-accessible scripts. The primary impact is high integrity loss; confidentiality is not directly affected, but availability may be impacted if critical system files are overwritten (GitHub Advisory, pyload Advisory).
A proof-of-concept exploit with step-by-step payload details is publicly documented in the GitHub Security Advisory, making exploitation straightforward for any authenticated attacker with MODIFY permission. As of the time of reporting, there is no evidence of active in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.022% (6th percentile), indicating a currently low probability of exploitation in the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, pyload Advisory).
edit_package() function.pack_folder parameter using recursive traversal sequences, e.g., pack_folder=..././..././..././tmp. After the single-pass ../ replacement, this resolves to ../../../tmp.edit_package() with the malicious path./tmp) outside the intended storage directory, which can be leveraged for further exploitation such as placing a malicious script in a cron directory or overwriting a configuration file to achieve code execution (GitHub Advisory, pyload Advisory).pack_folder values with patterns like ..././, ....//, or other obfuscated traversal sequences./tmp, /etc, cron directories, or web-accessible paths); newly created or modified files owned by the pyload process user in unexpected locations.edit_package() calls with pack_folder values containing traversal sequences; web server access logs with requests to the package edit endpoint from unusual source IPs or at unusual times.Update pyload-ng to version 0.5.0b3.dev97 or later, which contains the fix for this vulnerability. As a workaround prior to patching, restrict MODIFY permissions to only fully trusted users and limit network access to the pyload web interface. The vendor recommends replacing the single-pass string replacement with proper path canonicalization (e.g., using os.path.realpath() or equivalent) and validating that the resolved path remains within the intended storage directory (GitHub Advisory, pyload Advisory).
The vulnerability was reported by researchers BaranTeyin1 and MetinGerdan and published by GammaC0de to the pyload repository on March 4, 2026. Coverage has appeared on threat intelligence aggregators and advisory sites including GitLab Advisories and yazoul.net, with a brief mention on Bluesky social media. No major vendor statements or significant mainstream media coverage have been identified beyond the official advisory (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."