CVE-2026-32808: pyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password Verification
pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to path traversal during password verification of certain encrypted 7z archives (encrypted files with non-encrypted headers), causing arbitrary file deletion outside of the extraction directory. During password verification, pyLoad derives an archive entry name from 7z listing output and treats it as a filesystem path without constraining it to the extraction directory. This issue has been fixed in version 0.5.0b3.dev97.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32808?
CVE-2026-32808 has a high severity rating due to its capability to allow arbitrary file deletion.
How do I fix CVE-2026-32808?
To fix CVE-2026-32808, upgrade pyLoad to version 0.5.0b3.dev97 or later.
What is the impact of CVE-2026-32808?
The impact of CVE-2026-32808 includes the potential for unauthorized deletion of files on the server.
Which versions of pyLoad are affected by CVE-2026-32808?
All versions of pyLoad before 0.5.0b3.dev97 are affected by CVE-2026-32808.
Is there any way to mitigate CVE-2026-32808?
The only reliable mitigation for CVE-2026-32808 is to apply the software update to a secured version.