Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42314

Опубликовано: 11 мая 2026
Источник: debian
EPSS Низкий

Описание

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ after replacement (partial removal), leaving .. which can be exploited when the path is later resolved by the OS. This vulnerability is fixed in 0.5.0b3.dev100.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pyloaditppackage

EPSS

Процентиль: 27%
0.00342
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ after replacement (partial removal), leaving .. which can be exploited when the path is later resolved by the OS. This vulnerability is fixed in 0.5.0b3.dev100.

CVSS3: 6.5
github
3 месяца назад

PyLoad Vulnerable to Path Traversal via Package Folder Name

EPSS

Процентиль: 27%
0.00342
Низкий