Skip to main content

Pyload ng: pyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo (CVE-2026-75597)

0
Medium
Published: 10/09/2026 (10/09/2026, 16:40:30 UTC)
Source: GCVE Database
Product: pyload-ng

Description

pyLoad-ng versions prior to 0.5.0b3.dev101 have an unauthenticated access vulnerability in the /web/<path:filename> route, which allows rendering of sensitive Jinja2 templates without authentication. This bypasses the access control enforced on other direct routes. Additionally, an exception handling bug leaks internal error details, including Jinja2 variable names, in HTTP 500 responses to unauthenticated users. This enables attackers to enumerate valid templates and gain insight into internal application structure and system information.

CVSS v3.1

Score 5.3medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected software

PyPIghsa
pyload-ng
Affected versions
<0.5.0b3.dev101

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/09/2026, 22:55:02 UTC

Technical Analysis

The /web/<path:filename> route in pyLoad-ng's web UI lacks authentication protection, unlike other sensitive routes protected by @login_required decorators. This allows unauthenticated users to render arbitrary templates by specifying their filename in the URL path. Furthermore, an exception attribute typo in the error handler causes internal exception details to be leaked in HTTP 500 responses. Specifically, the handler incorrectly references exc.desc instead of exc.description, causing the raw exception string (e.g., 'conf' is undefined) to be included in the error page. This combination allows unauthenticated attackers to bypass access controls, view sensitive system information pages, and enumerate valid template names by observing HTTP response codes.

Potential Impact

An unauthenticated remote attacker can bypass authentication controls to render sensitive application templates, including system information pages revealing Python version, OS platform, installation and config folder paths, and WebUI port. The attacker can also enumerate valid template names by differentiating HTTP 200 and 500 responses. Internal Jinja2 variable names and error details are leaked in HTTP 500 responses, potentially aiding further reconnaissance. There is no indication of direct code execution or data modification from this vulnerability.

Mitigation Recommendations

A patch is available for this vulnerability. Users should upgrade to pyLoad-ng version 0.5.0b3.dev101 or later, where the /web/<path:filename> route is protected by authentication and the exception handling bug is fixed. Until patched, restrict access to the web UI to trusted networks or users to mitigate unauthorized template rendering and information leakage.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-j92p-c242-7hfx
Osv Schema Version
1.4.0
Aliases
["CVE-2026-75597"]
Ecosystems
["PyPI"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6ac96e662cdf04f65689a93f

Added to database: 10/09/2026, 22:44:54 UTC

Last enriched: 10/09/2026, 22:55:02 UTC

Last updated: 10/09/2026, 22:55:02 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses