<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:31:27 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-45306 — pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-45306</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; pyload&lt;/p&gt;
&lt;p&gt;pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR or userdir, but does NOT protect the Flask session directory (/tmp/pyLoad/flask). An authenticated attacker can set storage_folder to the session directory and download session files of other users via /files/get/, leading to account takeover. This vulnerability is fixed in 0.5.0b3.dev100.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; pyload&lt;/p&gt;
&lt;p&gt;pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR or userdir, but does NOT protect the Flask session directory (/tmp/pyLoad/flask). An authenticated attacker can set storage_folder to the session directory and download session files of other users via /files/get/, leading to account takeover. This vulnerability is fixed in 0.5.0b3.dev100.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-45306</guid>
    </item>
    <item>
      <title>GHSA-w727-595x-pc3r — pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w727-595x-pc3r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;## Summary
The fix for CVE-2026-33509 prevents setting `storage_folder` inside `PKGDIR` or `userdir`, but does NOT protect the Flask session directory (`/tmp/pyLoad/flask`). An authenticated attacker can set `storage_folder` to the session directory and download session files of other users via `/files/get/`, leading to account takeover.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The fix in `src/pyload/core/api/__init__.py`:&lt;/p&gt;
&lt;p&gt;```python
directories = [PKGDIR, userdir]
if any(directories[0].startswith(d) for d in directories[1:]):
    return  # blocked
```&lt;/p&gt;
&lt;p&gt;But the Flask session directory is:
```python
session_storage_path = os.path.join(api.get_cachedir(), &amp;#34;flask&amp;#34;)
# = /tmp/pyLoad/flask  ← NOT blocked by fix
```&lt;/p&gt;
&lt;p&gt;## Attack Chain&lt;/p&gt;
&lt;p&gt;1. Attacker (admin) sets `storage_folder = /tmp/pyLoad/flask`
2. Fix does NOT block this — `/tmp/pyLoad/flask` not inside `PKGDIR` or `userdir`
3. Attacker requests `GET /files/get/&amp;lt;victim_session_filename&amp;gt;`
4. `send_from_directory(&amp;#39;/tmp/pyLoad/flask&amp;#39;, session_file)` serves victim&amp;#39;s session
5. Attacker uses stolen session → **Account Takeover**&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;592&amp;#34; height=&amp;#34;408&amp;#34; alt=&amp;#34;POC&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/936b9f56-325b-437d-9edd-e0d5bb995187&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;```python
import os&lt;/p&gt;
&lt;p&gt;PKGDIR = &amp;#34;/usr/lib/python3/dist-packages/pyload&amp;#34;
userdir = os.path.expanduser(&amp;#34;~/.pyload&amp;#34;)
session_dir = &amp;#34;/tmp/pyLoad/flask&amp;#34;&lt;/p&gt;
&lt;p&gt;correct_case = lambda x: x
directories = [
    correct_case(os.path.join(os.path.realpath(d), &amp;#34;&amp;#34;))
    for d in [session_dir, PKGDIR, userdir]
]
blocked = an…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyload-ng&lt;/p&gt;
&lt;p&gt;## Summary
The fix for CVE-2026-33509 prevents setting `storage_folder` inside `PKGDIR` or `userdir`, but does NOT protect the Flask session directory (`/tmp/pyLoad/flask`). An authenticated attacker can set `storage_folder` to the session directory and download session files of other users via `/files/get/`, leading to account takeover.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The fix in `src/pyload/core/api/__init__.py`:&lt;/p&gt;
&lt;p&gt;```python
directories = [PKGDIR, userdir]
if any(directories[0].startswith(d) for d in directories[1:]):
    return  # blocked
```&lt;/p&gt;
&lt;p&gt;But the Flask session directory is:
```python
session_storage_path = os.path.join(api.get_cachedir(), &amp;#34;flask&amp;#34;)
# = /tmp/pyLoad/flask  ← NOT blocked by fix
```&lt;/p&gt;
&lt;p&gt;## Attack Chain&lt;/p&gt;
&lt;p&gt;1. Attacker (admin) sets `storage_folder = /tmp/pyLoad/flask`
2. Fix does NOT block this — `/tmp/pyLoad/flask` not inside `PKGDIR` or `userdir`
3. Attacker requests `GET /files/get/&amp;lt;victim_session_filename&amp;gt;`
4. `send_from_directory(&amp;#39;/tmp/pyLoad/flask&amp;#39;, session_file)` serves victim&amp;#39;s session
5. Attacker uses stolen session → **Account Takeover**&lt;/p&gt;
&lt;p&gt;## PoC&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;592&amp;#34; height=&amp;#34;408&amp;#34; alt=&amp;#34;POC&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/936b9f56-325b-437d-9edd-e0d5bb995187&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;```python
import os&lt;/p&gt;
&lt;p&gt;PKGDIR = &amp;#34;/usr/lib/python3/dist-packages/pyload&amp;#34;
userdir = os.path.expanduser(&amp;#34;~/.pyload&amp;#34;)
session_dir = &amp;#34;/tmp/pyLoad/flask&amp;#34;&lt;/p&gt;
&lt;p&gt;correct_case = lambda x: x
directories = [
    correct_case(os.path.join(os.path.realpath(d), &amp;#34;&amp;#34;))
    for d in [session_dir, PKGDIR, userdir]
]
blocked = an…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w727-595x-pc3r</guid>
    </item>
  </channel>
</rss>
