Junglewise Threat Intelligence

CVE-2026-35464: PYSEC-2026-2989 - pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for

CVE-2026-35464 · Severity: low · CVSS 3.1 · Published 2026-07-13

Technologies: pyload-ng (PyPI). Vendors: PyPI.

Executive brief

pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)

Affected products

  • PyPI pyload-ng

Related threats