CVE-2026-29778: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-29778 is a relative path traversal vulnerability in the edit_package() function of pyload-ng, an open-source download manager written in Python. It allows authenticated users with MODIFY permission to write files to arbitrary locations on the filesystem outside the intended storage directory. The vulnerability affects pyload-ng versions >= 0.5.0b3.dev13 and <= 0.5.0b3.dev96, and was disclosed on March 4, 2026, with a patch released in version 0.5.0b3.dev97. The GitHub Advisory Database assigns a CVSS v3.1 score of 7.1 (High), while Feedly reports a base score of 6.5 (Medium) (GitHub Advisory, pyload Advisory).

Technical details

The root cause is classified as CWE-23 (Relative Path Traversal): the edit_package() function sanitizes the pack_folder parameter using a single-pass string replacement that removes occurrences of ../, but does not iterate or canonicalize the result. An attacker can bypass this protection by submitting a crafted recursive traversal sequence such as pack_folder=..././..././..././tmp; after the single-pass replacement strips the embedded ../ fragments, the remaining string resolves to ../../../tmp, effectively escaping the intended storage directory. The attack vector is network-based, requires low privileges (an authenticated account with MODIFY permission), and no user interaction (GitHub Advisory, pyload Advisory).

Impact

Successful exploitation allows an authenticated attacker to write files to arbitrary locations on the server filesystem, such as /tmp or other system directories, outside the intended pyload storage path. This arbitrary file write primitive can be chained to achieve remote code execution — for example, by overwriting configuration files, cron jobs, or placing web-accessible scripts. The primary impact is high integrity loss; confidentiality is not directly affected, but availability may be impacted if critical system files are overwritten (GitHub Advisory, pyload Advisory).

Exploitability

A proof-of-concept exploit with step-by-step payload details is publicly documented in the GitHub Security Advisory, making exploitation straightforward for any authenticated attacker with MODIFY permission. As of the time of reporting, there is no evidence of active in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.022% (6th percentile), indicating a currently low probability of exploitation in the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, pyload Advisory).

Exploitation steps

  1. Reconnaissance: Identify pyload-ng instances running versions >= 0.5.0b3.dev13 and <= 0.5.0b3.dev96, accessible over the network (e.g., via Shodan or direct enumeration of the pyload web interface).
  2. Authentication: Log in to the pyload web interface using valid credentials for an account that holds MODIFY permission on packages.
  3. Identify target package: Navigate to an existing package or create one to obtain a valid package ID for use with the edit_package() function.
  4. Craft malicious payload: Construct a request to the package edit endpoint with a crafted pack_folder parameter using recursive traversal sequences, e.g., pack_folder=..././..././..././tmp. After the single-pass ../ replacement, this resolves to ../../../tmp.
  5. Submit request: Send the crafted HTTP request (e.g., via the web UI or direct API call) to trigger edit_package() with the malicious path.
  6. Achieve arbitrary file write: The application writes files to the attacker-controlled path (e.g., /tmp) outside the intended storage directory, which can be leveraged for further exploitation such as placing a malicious script in a cron directory or overwriting a configuration file to achieve code execution (GitHub Advisory, pyload Advisory).

Indicators of compromise

  • Network: Unusual HTTP POST/PUT requests to pyload's package edit endpoint containing pack_folder values with patterns like ..././, ....//, or other obfuscated traversal sequences.
  • File System: Unexpected files appearing in directories outside the configured pyload storage path (e.g., /tmp, /etc, cron directories, or web-accessible paths); newly created or modified files owned by the pyload process user in unexpected locations.
  • Logs: pyload application logs showing edit_package() calls with pack_folder values containing traversal sequences; web server access logs with requests to the package edit endpoint from unusual source IPs or at unusual times.
  • Process: Unexpected processes spawned by the pyload service user, particularly shells or interpreters, which may indicate a follow-on code execution attempt after a successful file write (GitHub Advisory).

Mitigation and workarounds

Update pyload-ng to version 0.5.0b3.dev97 or later, which contains the fix for this vulnerability. As a workaround prior to patching, restrict MODIFY permissions to only fully trusted users and limit network access to the pyload web interface. The vendor recommends replacing the single-pass string replacement with proper path canonicalization (e.g., using os.path.realpath() or equivalent) and validating that the resolved path remains within the intended storage directory (GitHub Advisory, pyload Advisory).

Community reactions

The vulnerability was reported by researchers BaranTeyin1 and MetinGerdan and published by GammaC0de to the pyload repository on March 4, 2026. Coverage has appeared on threat intelligence aggregators and advisory sites including GitLab Advisories and yazoul.net, with a brief mention on Bluesky social media. No major vendor statements or significant mainstream media coverage have been identified beyond the official advisory (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management