<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:17:36 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-45348 — pyLoad: Stored XSS in Downloads view via unsanitized link URL in packages.js template literal</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-45348</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; pyload&lt;/p&gt;
&lt;p&gt;pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/templates/js/packages.js:172 interpolates a stored link URL into a template literal inside single-quoted HTML and then writes the result to the DOM via $(div).html(html). No escaping runs between the API value and innerHTML. An attacker (Alice) who can submit a package link puts a single quote plus event handler into the URL, breaks out of the attribute, and executes JavaScript in every operator&amp;#39;s browser that opens the downloads view. The theme does not set a Content Security Policy that restricts inline script or event handlers. This vulnerability is fixed in 0.5.0b3.dev100.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; pyload&lt;/p&gt;
&lt;p&gt;pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/templates/js/packages.js:172 interpolates a stored link URL into a template literal inside single-quoted HTML and then writes the result to the DOM via $(div).html(html). No escaping runs between the API value and innerHTML. An attacker (Alice) who can submit a package link puts a single quote plus event handler into the URL, breaks out of the attribute, and executes JavaScript in every operator&amp;#39;s browser that opens the downloads view. The theme does not set a Content Security Policy that restricts inline script or event handlers. This vulnerability is fixed in 0.5.0b3.dev100.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-45348</guid>
    </item>
    <item>
      <title>GHSA-fcjq-435v-jx94 — pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fcjq-435v-jx94</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `packages.js` template at `src/pyload/webui/app/themes/modern/templates/js/packages.js:172` interpolates a stored link URL into a template literal inside single-quoted HTML and then writes the result to the DOM via `$(div).html(html)`. No escaping runs between the API value and `innerHTML`. An attacker (Alice) who can submit a package link puts a single quote plus event handler into the URL, breaks out of the attribute, and executes JavaScript in every operator&amp;#39;s browser that opens the downloads view. The theme does not set a Content Security Policy that restricts inline script or event handlers.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;**Sink**: `src/pyload/webui/app/themes/modern/templates/js/packages.js:165-188`:&lt;/p&gt;
&lt;p&gt;```javascript
const html = `
    &amp;lt;span class=&amp;#39;child_status&amp;#39;&amp;gt;
      &amp;lt;span style=&amp;#39;margin-right: 2px;color: #337ab7;&amp;#39; class=&amp;#39;${link.icon}&amp;#39;&amp;gt;&amp;lt;/span&amp;gt;
    &amp;lt;/span&amp;gt;
    &amp;lt;span style=&amp;#39;font-size: 16px; font-weight: bold;&amp;#39;&amp;gt;
      &amp;lt;a onclick=&amp;#39;return false&amp;#39; href=&amp;#39;${link.url}&amp;#39;&amp;gt;${link.name}&amp;lt;/a&amp;gt;
    &amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;
    &amp;lt;div class=&amp;#39;child_secrow&amp;#39; ...&amp;gt;
      &amp;lt;span class=&amp;#39;child_status&amp;#39; ...&amp;gt;${link.statusmsg}&amp;lt;/span&amp;gt;&amp;amp;nbsp;${link.error}&amp;amp;nbsp;
      &amp;lt;span class=&amp;#39;child_status&amp;#39; ...&amp;gt;${link.format_size}&amp;lt;/span&amp;gt;
      &amp;lt;span class=&amp;#39;child_status&amp;#39; ...&amp;gt; ${link.plugin}&amp;lt;/span&amp;gt;...
    &amp;lt;/div&amp;gt;`;&lt;/p&gt;
&lt;p&gt;const div = document.createElement(&amp;#34;div&amp;#34;);
$(div).attr(&amp;#34;id&amp;#34;, `file_${link.id}`);
$(div).css(&amp;#34;padding-left&amp;#34;, &amp;#34;30px&amp;#34;);
$(div).css(&amp;#34;cursor&amp;#34;, &amp;#34;grab&amp;#34;);
$(div).addClass(&amp;#34;child&amp;#34;);
$(div).html(html);
```&lt;/p&gt;
&lt;p&gt;`link.url` flows in from `/a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `packages.js` template at `src/pyload/webui/app/themes/modern/templates/js/packages.js:172` interpolates a stored link URL into a template literal inside single-quoted HTML and then writes the result to the DOM via `$(div).html(html)`. No escaping runs between the API value and `innerHTML`. An attacker (Alice) who can submit a package link puts a single quote plus event handler into the URL, breaks out of the attribute, and executes JavaScript in every operator&amp;#39;s browser that opens the downloads view. The theme does not set a Content Security Policy that restricts inline script or event handlers.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;**Sink**: `src/pyload/webui/app/themes/modern/templates/js/packages.js:165-188`:&lt;/p&gt;
&lt;p&gt;```javascript
const html = `
    &amp;lt;span class=&amp;#39;child_status&amp;#39;&amp;gt;
      &amp;lt;span style=&amp;#39;margin-right: 2px;color: #337ab7;&amp;#39; class=&amp;#39;${link.icon}&amp;#39;&amp;gt;&amp;lt;/span&amp;gt;
    &amp;lt;/span&amp;gt;
    &amp;lt;span style=&amp;#39;font-size: 16px; font-weight: bold;&amp;#39;&amp;gt;
      &amp;lt;a onclick=&amp;#39;return false&amp;#39; href=&amp;#39;${link.url}&amp;#39;&amp;gt;${link.name}&amp;lt;/a&amp;gt;
    &amp;lt;/span&amp;gt;&amp;lt;br/&amp;gt;
    &amp;lt;div class=&amp;#39;child_secrow&amp;#39; ...&amp;gt;
      &amp;lt;span class=&amp;#39;child_status&amp;#39; ...&amp;gt;${link.statusmsg}&amp;lt;/span&amp;gt;&amp;amp;nbsp;${link.error}&amp;amp;nbsp;
      &amp;lt;span class=&amp;#39;child_status&amp;#39; ...&amp;gt;${link.format_size}&amp;lt;/span&amp;gt;
      &amp;lt;span class=&amp;#39;child_status&amp;#39; ...&amp;gt; ${link.plugin}&amp;lt;/span&amp;gt;...
    &amp;lt;/div&amp;gt;`;&lt;/p&gt;
&lt;p&gt;const div = document.createElement(&amp;#34;div&amp;#34;);
$(div).attr(&amp;#34;id&amp;#34;, `file_${link.id}`);
$(div).css(&amp;#34;padding-left&amp;#34;, &amp;#34;30px&amp;#34;);
$(div).css(&amp;#34;cursor&amp;#34;, &amp;#34;grab&amp;#34;);
$(div).addClass(&amp;#34;child&amp;#34;);
$(div).html(html);
```&lt;/p&gt;
&lt;p&gt;`link.url` flows in from `/a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fcjq-435v-jx94</guid>
    </item>
  </channel>
</rss>
