CVE-2026-75597: pyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo
Summary
The /web/<path:filename> route in src/pyload/webui/app/blueprints/appblueprint.py renders Jinja2 templates without any authentication requirement. Every equivalent direct route (/logs, /settings, /queue, /dashboard, etc.) is protected by @loginrequired, but the underlying templates for all of these pages are accessible unauthenticated via this endpoint. Combined with an exception attribute typo in src/pyload/webui/app/handlers.py (exc.desc instead of exc.description), internal Jinja2 variable names are leaked in HTTP 500 response bodies to unauthenticated callers. An attacker can also enumerate all valid template names by observing 200 vs 500 response differentiation.
Details
Bug 1 — Missing authentication on /web/<path:filename>
File: src/pyload/webui/app/blueprints/appblueprint.py, lines 32–36
python @bp.route("/web/<path:filename>", endpoint="web") def render(filename): # ← no @loginrequired mimetype = mimetypes.guesstype(filename)[0] or "text/html" data = rendertemplate(filename) return flask.Response(data, mimetype=mimetype)
Every other sensitive route in the same file is protected:
python @bp.route("/logs", ...) @loginrequired("LIST") # protected
@bp.route("/settings", ...) @loginrequired("SETTINGS") # protected
@bp.route("/files", ...) @loginrequired("DOWNLOAD") # protected
The /web/<path:filename> route has no such decorator, allowing any unauthenticated HTTP client to render arbitrary templates by supplying their filename in the URL path.
Bug 2 — Exception attribute typo causes internal details in error responses
File: src/pyload/webui/app/handlers.py, lines 12–20
python def handleexceptionerror(exc): try: code = exc.code desc = exc.desc # BUG: attribute does not exist on standard exceptions except AttributeError: # always raised — falls here for every exception code = 500 desc = exc # raw exception object assigned to desc message = f"Error {code}: {desc}" # str(exc) embedded in response body return rendertemplate("error.html", messages=[message]), code
exc.desc does not exist on standard Python or Jinja2 exceptions. The AttributeError branch is always taken for template rendering failures. desc is set to the raw exception object, and str(exc) is embedded in the HTML response body returned to the unauthenticated caller. For a UndefinedError this produces 'conf' is undefined. For TemplateNotFound it produces the template filename.
PoC
Tested against pyload-ng develop branch (0.5.0b3.dev), default install, no authentication cookies or credentials used in any request.
Test 1 — Unauthenticated page render confirmed (HTTP 200) bash curl -si http://TARGET:8000/web/logs.html | grep "HTTP\|title"
Test 2 — System info page with sensitive field labels rendered unauthenticated curl -s http://TARGET:8000/web/info.html | grep "Python Version\|Installation Folder\|Config Folder\|OS Platform" html
<dt><b>Python Version:</b></dt> <dt><b>OS Platform:</b></dt> <dt><b>Installation Folder:</b></dt> <dt><b>Config Folder:</b></dt>
Test 3 — Internal Jinja2 variable name leaked in HTTP 500 body (unauthenticated) curl -si http://TARGET:8000/web/settings.html | grep "HTTP\|Error" HTTP/1.1 500 INTERNAL SERVER ERROR <p><b>Error 500: 'conf' is undefined</b></p> Test 4 — Template enumeration via response code differentiation curl -o /dev/null -sw "%{httpcode}\n" http://TARGET:8000/web/logs.html curl -o /dev/null -sw "%{httpcode}\n" http://TARGET:8000/web/info.html curl -o /dev/null -sw "%{httpcode}\n" http://TARGET:8000/web/dashboard.html curl -o /dev/null -sw "%{httpcode}\n" http://TARGET:8000/web/settings.html curl -o /dev/null -sw "%{httpcode}\n" http://TARGET:8000/web/queue.html curl -o /dev/null -sw "%{httpcode}\n" http://TARGET:8000/web/collector.html curl -o /dev/null -sw "%{httpcode}\n" http://TARGET:8000/web/filemanager.html curl -o /dev/null -sw "%{httpcode}\n" http://TARGET:8000/web/nonexistentxyz.html 200 ← logs.html (exists, renders without auth) 200 ← info.html (exists, renders without auth) 200 ← dashboard.html (exists, renders without auth) 500 ← settings.html (exists, missing auth context — leaks 'conf' is undefined) 500 ← queue.html (exists, missing auth context) 500 ← collector.html (exists, missing auth context) 500 ← filemanager.html (exists, missing auth context) 500 ← nonexistentxyz (does not exist — same 500, no differentiation on miss)
###Impact An unauthenticated remote attacker can:
Render application page templates without any credentials, bypassing the access control model enforced on all direct routes Access the system information page (info.html) exposing field structure for Python version, OS platform, pyLoad version, installation folder, config folder, and WebUI port — values are populated via JS but field labels confirm application structure Access the full log viewer UI (logs.html) and download dashboard (dashboard.html) without authentication Extract internal Jinja2 template variable names from HTTP 500 response bodies ('conf' is undefined, etc.) Enumerate all valid template filenames by observing 200 vs 500 response codes
The access control inconsistency is the core issue: the authentication model enforced on direct routes is completely bypassed via the /web/<path:filename> endpoint. Any future template that renders sensitive data server-side would be immediately exposed to unauthenticated access through this route.
Other sources
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the /web/<path:filename> route in src/pyload/webui/app/blueprints/appblueprint.py renders Jinja2 templates without any authentication requirement. Every equivalent direct route (/logs, /settings, /queue, /dashboard, etc.) is protected by @loginrequired, but the underlying templates for all of these pages are accessible unauthenticated via this endpoint. Combined with an exception attribute typo in src/pyload/webui/app/handlers.py (exc.desc instead of exc.description), internal Jinja2 variable names are leaked in HTTP 500 response bodies to unauthenticated callers. An attacker can also enumerate all valid template names by observing 200 vs 500 response differentiation. Version 0.5.0b3.dev101 contains a patch.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pyload-ngto a version that resolves this vulnerability.Fixed in 0.5.0b3.dev101 - Upgrade
Upgrade
pyLoadto a version that resolves this vulnerability.Fixed in 0.5.0b3.dev101
Event History
Frequently Asked Questions
Which deployments are affected?
pyLoad versions prior to 0.5.0b3.dev101 are affected. The issue is remotely reachable over the network and does not require authentication or user interaction.
What can an unauthenticated attacker obtain?
An attacker can request templates through the /web/<path:filename> route, including templates corresponding to normally protected pages such as logs, settings, queue, and dashboard. They can also distinguish valid template names by 200 versus 500 responses and trigger HTTP 500 responses that leak internal Jinja2 variable names.
Is the normal authentication protection sufficient?
No. Although direct routes such as /logs, /settings, /queue, and /dashboard use login_required, their underlying templates remain accessible through the unauthenticated /web/<path:filename> route.
What version fixes the issue?
Version 0.5.0b3.dev101 contains the patch.