Pyload ng: pyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo (CVE-2026-75597)
Description
pyLoad-ng versions prior to 0.5.0b3.dev101 have an unauthenticated access vulnerability in the /web/<path:filename> route, which allows rendering of sensitive Jinja2 templates without authentication. This bypasses the access control enforced on other direct routes. Additionally, an exception handling bug leaks internal error details, including Jinja2 variable names, in HTTP 500 responses to unauthenticated users. This enables attackers to enumerate valid templates and gain insight into internal application structure and system information.
CVSS v3.1
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The /web/<path:filename> route in pyLoad-ng's web UI lacks authentication protection, unlike other sensitive routes protected by @login_required decorators. This allows unauthenticated users to render arbitrary templates by specifying their filename in the URL path. Furthermore, an exception attribute typo in the error handler causes internal exception details to be leaked in HTTP 500 responses. Specifically, the handler incorrectly references exc.desc instead of exc.description, causing the raw exception string (e.g., 'conf' is undefined) to be included in the error page. This combination allows unauthenticated attackers to bypass access controls, view sensitive system information pages, and enumerate valid template names by observing HTTP response codes.
Potential Impact
An unauthenticated remote attacker can bypass authentication controls to render sensitive application templates, including system information pages revealing Python version, OS platform, installation and config folder paths, and WebUI port. The attacker can also enumerate valid template names by differentiating HTTP 200 and 500 responses. Internal Jinja2 variable names and error details are leaked in HTTP 500 responses, potentially aiding further reconnaissance. There is no indication of direct code execution or data modification from this vulnerability.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade to pyLoad-ng version 0.5.0b3.dev101 or later, where the /web/<path:filename> route is protected by authentication and the exception handling bug is fixed. Until patched, restrict access to the web UI to trusted networks or users to mitigate unauthorized template rendering and information leakage.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-j92p-c242-7hfx
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-75597"]
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ac96e662cdf04f65689a93f
Added to database: 10/09/2026, 22:44:54 UTC
Last enriched: 10/09/2026, 22:55:02 UTC
Last updated: 10/09/2026, 22:55:02 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.