CVE-2026-75597: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-75597 is an authentication bypass and information disclosure vulnerability in pyLoad (pyload-ng), a free and open-source Python download manager. The /web/<path:filename> route in src/pyload/webui/app/blueprints/app_blueprint.py renders Jinja2 templates without any authentication check, while all equivalent direct routes (/logs, /settings, /queue, /dashboard, etc.) are protected by @login_required. A secondary bug — an exception attribute typo (exc.desc instead of exc.description) in src/pyload/webui/app/handlers.py — causes internal Jinja2 variable names to leak in HTTP 500 response bodies to unauthenticated callers. All versions up to and including 0.5.0b3.dev100 are affected; the vulnerability was first published on July 8, 2026, and added to the GitHub Advisory Database on October 9, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).

Technical details

The root cause is a missing authentication decorator (CWE-306) on the /web/<path:filename> Flask route, combined with an error-handling bug that generates error messages containing sensitive information (CWE-209). Because the render() function in app_blueprint.py lacks @login_required, any unauthenticated HTTP client can request any template by name (e.g., GET /web/logs.html). When a template requires context variables not available in an unauthenticated session (e.g., conf for settings.html), Jinja2 raises an UndefinedError; the buggy exception handler then embeds the raw exception string — such as 'conf' is undefined — directly into the HTTP 500 response body, leaking internal variable names. An attacker can also enumerate valid template filenames by observing the difference between HTTP 200 (template renders successfully) and HTTP 500 (template exists but fails due to missing context) responses, though non-existent templates also return 500, limiting precision (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows an unauthenticated remote attacker to render admin-only page templates — including logs.html, info.html, and dashboard.html — without any credentials, bypassing the access control model enforced on all direct routes. The info.html template exposes field structure for Python version, OS platform, pyLoad version, installation folder, config folder, and WebUI port, which can aid further reconnaissance. Internal Jinja2 template variable names (e.g., conf) are leaked via HTTP 500 error bodies, and valid template filenames can be enumerated. There is no integrity or availability impact; the vulnerability is limited to confidentiality (low), with no evidence of lateral movement capability (GitHub Advisory).

Exploitability

A proof-of-concept (PoC) consisting of concrete curl commands is publicly available in the GitHub Security Advisory, requiring no authentication, no special tools, and no user interaction — making the attack fully automatable (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "poc" and automatable with partial technical impact. The EPSS score is 0.0, and there is no evidence of active in-the-wild exploitation or inclusion in the CISA KEV catalog at this time. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing pyLoad WebUI instances (default port 8000) running pyload-ng version <= 0.5.0b3.dev100 using tools like Shodan (port:8000 pyload) or Censys.
  2. Confirm authentication bypass: Send an unauthenticated GET request to a known template: curl -si http://TARGET:8000/web/logs.html | grep "HTTP\|title". A 200 response with page HTML confirms the vulnerability is present.
  3. Access sensitive system information: Request info.html to retrieve field labels for Python version, OS platform, installation folder, config folder, and WebUI port: curl -si http://TARGET:8000/web/info.html.
  4. Trigger error-based information leakage: Request a template that requires authenticated context variables to leak internal Jinja2 variable names: curl -si http://TARGET:8000/web/settings.html | grep "Error". A 500 response body containing Error 500: 'conf' is undefined confirms the secondary bug.
  5. Enumerate valid template names: Loop over candidate filenames and record HTTP status codes — 200 indicates a renderable template, 500 may indicate an existing template with missing context: curl -o /dev/null -sw "%{http_code}\n" http://TARGET:8000/web/<candidate>.html. Note that non-existent templates also return 500, so differentiation is imprecise.
  6. Compile reconnaissance data: Aggregate rendered HTML content and leaked variable names to map application structure for potential follow-on attacks (GitHub Advisory).

Indicators of compromise

  • Network: Unauthenticated HTTP GET requests to /web/*.html endpoints (e.g., /web/logs.html, /web/info.html, /web/settings.html, /web/dashboard.html) from external or unexpected IP addresses on port 8000.
  • Network: Rapid sequential GET requests to multiple /web/<filename>.html paths from a single source IP, consistent with template enumeration activity.
  • Logs: Web server access logs showing HTTP 200 responses to /web/logs.html, /web/info.html, or /web/dashboard.html without an associated authenticated session cookie.
  • Logs: HTTP 500 responses to /web/settings.html, /web/queue.html, /web/collector.html, or /web/filemanager.html from unauthenticated clients, indicating attempted context-variable leakage.
  • Logs: Absence of session/authentication tokens in requests that successfully retrieve template content from the /web/ route (GitHub Advisory).

Mitigation and workarounds

Upgrade pyload-ng to version 0.5.0b3.dev101 or later, which adds an authentication check to the /web/<path:filename> route (redirecting unauthenticated users to the login page, except for login.html) and replaces the verbose exception handler with a generic error message (Patch Commit, GitHub Advisory). If immediate patching is not possible, implement network-level access controls (firewall rules or reverse proxy authentication) to restrict access to the pyLoad WebUI port (default 8000) to trusted IP addresses only. Avoid exposing the pyLoad WebUI directly to the internet.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-108258MEDIUM6.9
  • Python logoPython
  • shiny
NoYesOct 09, 2026
CVE-2026-48484MEDIUM6.5
  • Python logoPython
  • pyload-ng
NoYesOct 09, 2026
GHSA-p3pr-8f3m-4qp8MEDIUM6.4
  • Python logoPython
  • pyload-ng
NoNoOct 09, 2026
CVE-2026-107841MEDIUM5.7
  • Python logoPython
  • pacioli-guard
NoYesOct 09, 2026
CVE-2026-75597MEDIUM5.3
  • Python logoPython
  • pyload-ng
NoYesOct 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management