PT-2026-27492 · Pyload · Pyload
Yueyuel
·
Published
2026-03-24
·
Updated
2026-03-25
·
CVE-2026-33511
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pyLoad versions 0.4.20 through 0.5.0b3.dev96
Description
pyLoad, a download manager written in Python, contains a flaw in its ClickNLoad feature. The
local check decorator can be circumvented through HTTP Host header spoofing. This allows unauthenticated remote attackers to access endpoints restricted to localhost. Successful exploitation enables attackers to inject arbitrary downloads, write files to the storage directory, and execute JavaScript code.Recommendations
Update to version 0.5.0b3.dev97 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyload