PT-2026-40426 · Pyload · Pyload

Nssys

·

Published

2026-05-12

·

Updated

2026-05-28

·

CVE-2026-45306

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions pyLoad (affected versions not specified)
Description An authenticated attacker with administrative privileges can achieve account takeover by stealing session files of other users. The issue arises because the software fails to block the storage folder variable from being set to the Flask session directory, typically located at '/tmp/pyLoad/flask'. By setting the storage folder to this path, an attacker can use the '/files/get/' endpoint to download session files, allowing them to impersonate other users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2026-45306
GHSA-W727-595X-PC3R

Affected Products

Pyload