
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75597 is an authentication bypass and information disclosure vulnerability in pyLoad (pyload-ng), a free and open-source Python download manager. The /web/<path:filename> route in src/pyload/webui/app/blueprints/app_blueprint.py renders Jinja2 templates without any authentication check, while all equivalent direct routes (/logs, /settings, /queue, /dashboard, etc.) are protected by @login_required. A secondary bug — an exception attribute typo (exc.desc instead of exc.description) in src/pyload/webui/app/handlers.py — causes internal Jinja2 variable names to leak in HTTP 500 response bodies to unauthenticated callers. All versions up to and including 0.5.0b3.dev100 are affected; the vulnerability was first published on July 8, 2026, and added to the GitHub Advisory Database on October 9, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).
The root cause is a missing authentication decorator (CWE-306) on the /web/<path:filename> Flask route, combined with an error-handling bug that generates error messages containing sensitive information (CWE-209). Because the render() function in app_blueprint.py lacks @login_required, any unauthenticated HTTP client can request any template by name (e.g., GET /web/logs.html). When a template requires context variables not available in an unauthenticated session (e.g., conf for settings.html), Jinja2 raises an UndefinedError; the buggy exception handler then embeds the raw exception string — such as 'conf' is undefined — directly into the HTTP 500 response body, leaking internal variable names. An attacker can also enumerate valid template filenames by observing the difference between HTTP 200 (template renders successfully) and HTTP 500 (template exists but fails due to missing context) responses, though non-existent templates also return 500, limiting precision (GitHub Advisory, Patch Commit).
Successful exploitation allows an unauthenticated remote attacker to render admin-only page templates — including logs.html, info.html, and dashboard.html — without any credentials, bypassing the access control model enforced on all direct routes. The info.html template exposes field structure for Python version, OS platform, pyLoad version, installation folder, config folder, and WebUI port, which can aid further reconnaissance. Internal Jinja2 template variable names (e.g., conf) are leaked via HTTP 500 error bodies, and valid template filenames can be enumerated. There is no integrity or availability impact; the vulnerability is limited to confidentiality (low), with no evidence of lateral movement capability (GitHub Advisory).
A proof-of-concept (PoC) consisting of concrete curl commands is publicly available in the GitHub Security Advisory, requiring no authentication, no special tools, and no user interaction — making the attack fully automatable (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "poc" and automatable with partial technical impact. The EPSS score is 0.0, and there is no evidence of active in-the-wild exploitation or inclusion in the CISA KEV catalog at this time. No threat actor attribution has been reported.
pyload-ng version <= 0.5.0b3.dev100 using tools like Shodan (port:8000 pyload) or Censys.curl -si http://TARGET:8000/web/logs.html | grep "HTTP\|title". A 200 response with page HTML confirms the vulnerability is present.info.html to retrieve field labels for Python version, OS platform, installation folder, config folder, and WebUI port: curl -si http://TARGET:8000/web/info.html.curl -si http://TARGET:8000/web/settings.html | grep "Error". A 500 response body containing Error 500: 'conf' is undefined confirms the secondary bug.curl -o /dev/null -sw "%{http_code}\n" http://TARGET:8000/web/<candidate>.html. Note that non-existent templates also return 500, so differentiation is imprecise./web/*.html endpoints (e.g., /web/logs.html, /web/info.html, /web/settings.html, /web/dashboard.html) from external or unexpected IP addresses on port 8000./web/<filename>.html paths from a single source IP, consistent with template enumeration activity./web/logs.html, /web/info.html, or /web/dashboard.html without an associated authenticated session cookie./web/settings.html, /web/queue.html, /web/collector.html, or /web/filemanager.html from unauthenticated clients, indicating attempted context-variable leakage./web/ route (GitHub Advisory).Upgrade pyload-ng to version 0.5.0b3.dev101 or later, which adds an authentication check to the /web/<path:filename> route (redirecting unauthenticated users to the login page, except for login.html) and replaces the verbose exception handler with a generic error message (Patch Commit, GitHub Advisory). If immediate patching is not possible, implement network-level access controls (firewall rules or reverse proxy authentication) to restrict access to the pyLoad WebUI port (default 8000) to trusted IP addresses only. Avoid exposing the pyLoad WebUI directly to the internet.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."