SCA: security update for pyload-ng (GHSA-j92p-c242-7hfx)

medium Tenable Self-Hosted Container Security Plugin ID 474037

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the
`/web/<path:filename>` route in `src/pyload/webui/app/blueprints/app_blueprint.py` renders Jinja2
templates without any authentication requirement. Every equivalent direct route (`/logs`, `/settings`,
`/queue`, `/dashboard`, etc.) is protected by `@login_required`, but the underlying templates for all of
these pages are accessible unauthenticated via this endpoint. Combined with an exception attribute typo in
`src/pyload/webui/app/handlers.py` (`exc.desc` instead of `exc.description`), internal Jinja2 variable
names are leaked in HTTP 500 response bodies to unauthenticated callers. An attacker can also enumerate
all valid template names by observing 200 vs 500 response differentiation. Version 0.5.0b3.dev101 contains
a patch. (CVE-2026-75597)

Solution

Update the pyload-ng library and its related packages to version 0.5.0b3.dev101 or later.

See Also

https://github.com/advisories/GHSA-j92p-c242-7hfx

Plugin Details

Severity: Medium

ID: 474037

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/9/2026

Updated: 10/9/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2026-75597

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/9/2026

Vulnerability Publication Date: 10/9/2026

Reference Information

CVE: CVE-2026-75597