CVE-2026-42315·Python vulnerability
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_folder", there is no sanitization at all, allowing a user with Perms.MODIFY to specify arbitrary directories as download locations for a package. This vulnerability is fixed in 0.5.0b3.dev100.
- Severity
- high
- Software
- Python
- Fixed in
- 0.5.0b3.dev100
- Published
- 2026-05-11
Affected versions
Until: 0.5.0b3.dev100
Fixed in: 0.5.0b3.dev100
How to fix this CVE
Update pyLoad to version 0.5.0b3.dev100 or later to patch an arbitrary directory traversal vulnerability in the set_package_data() API function. Users with MODIFY permissions could previously specify unauthorized download locations by manipulating the _folder parameter without validation. Apply this update immediately to prevent privilege escalation and unauthorized file writes on affected systems.
sudo dnf update python3-pyloadDefensia detects this vulnerability
WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement API-level access controls restricting set_package_data() calls to trusted administrative users only; monitor for JSON payloads containing '_folder' keys with path traversal sequences (../, ..\, absolute paths); log all package configuration changes with full parameter values for audit trails.How to check if you are affected
- Step 1: Check installed pyLoad version by running: python3 -m pip show pyload | grep Version
- Step 2: Verify the API endpoint is accessible: curl -s http://localhost:8000/api/status (default port may vary)
- Step 3: Search application logs for set_package_data calls with _folder parameters: grep -r '_folder' /var/log/pyload/ /var/log/pyload-api/ 2>/dev/null | grep -i set_package
- Step 4: Confirm the fix by re-running pip show and verifying version is 0.5.0b3.dev100 or higher
FAQ
What is CVE-2026-42315?
CVE-2026-42315 is a path traversal vulnerability in pyLoad's set_package_data() API function that allows authenticated users with MODIFY permissions to specify arbitrary filesystem directories as download destinations, bypassing intended access controls.
Is CVE-2026-42315 being actively exploited?
No, CVE-2026-42315 is not currently listed on the CISA KEV catalog and no public exploits are available, though the vulnerability remains dangerous for multi-user deployments.
What versions of pyLoad are affected by CVE-2026-42315?
All versions of pyLoad prior to 0.5.0b3.dev100 are vulnerable; the vulnerability was introduced in an unknown earlier version and patched in the specified dev release.
How do I check if my server is vulnerable to CVE-2026-42315?
Run: python3 -m pip show pyload | grep Version; if the version is lower than 0.5.0b3.dev100, your installation is vulnerable.
Does Defensia detect CVE-2026-42315?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If pyLoad is installed on a monitored server, CVE-2026-42315 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-42315. Free for 1 server.
Get started free