Technology · PyPI
pyload-ng (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 47 vulnerabilities in pyload-ng (PyPI): 0 in the last 7 days and 23 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-48987, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 23
- Critical, all time
- 3
- Exploited in the wild
- 0
About pyload-ng (PyPI)
A download manager written in Python that supports various file hosting sites.
Latest pyload-ng (PyPI) vulnerabilities
- CVE-2026-48987: pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-48737: pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in…mediumCVSS 4.9EPSS 0.3%
- CVE-2026-35464: PYSEC-2026-2989 - pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code…lowCVSS 3.1EPSS 0.6%
- CVE-2026-33509: PYSEC-2026-2996 - pyLoad SETTINGS Permission Users Can Achieve Remote Code Execution via Unrestricted Reconnect Script…lowCVSS 3.1EPSS 0.6%
- CVE-2025-57751: PYSEC-2026-1815 - Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljsmediumCVSS 4EPSS 0.3%
- CVE-2025-55156: PYSEC-2026-1821 - PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parametermediumCVSS 4EPSS 0.3%
- CVE-2025-54140: PYSEC-2026-1823 - `pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File WritelowCVSS 3.1EPSS 0.7%
- CVE-2024-24808: PYSEC-2026-1817 - pyLoad open redirect vulnerability due to improper validation of the is_safe_url functionlowCVSS 3.1EPSS 0.5%
- CVE-2024-21644: PYSEC-2026-1820 - pyload Unauthenticated Flask Configuration Leakage vulnerabilitylowCVSS 3.1EPSS 42.4%
- CVE-2024-21645: PYSEC-2026-1818 - pyload Log Injection vulnerabilitylowCVSS 3.1EPSS 24.7%
- CVE-2023-47890: PYSEC-2026-1819 - Download to arbitrary folder can lead to RCElowCVSS 3.1EPSS 1.1%
- CVE-2023-0488: PYSEC-2026-907 - Cross-site Scripting in pyload-nglowCVSS 3.1EPSS 0.8%
- CVE-2023-0509: PYSEC-2026-903 - Improper Certificate Validation in pyload-nglowCVSS 3EPSS 0.5%
- CVE-2023-0434: PYSEC-2026-908 - Improper Input Validation in pyload-nglowCVSS 3EPSS 0.8%
- CVE-2023-0227: PYSEC-2026-906 - Pyload Insufficient Session Expiration vulnerabilitylowCVSS 3.1EPSS 0.7%
- CVE-2023-0057: PYSEC-2026-904 - pyLoad vulnerable to Improper Restriction of Rendered UI Layers or FrameslowCVSS 3.1EPSS 0.5%
- CVE-2023-0055: PYSEC-2026-905 - Pyload contains Sensitive Cookie in HTTPS Session Without 'Secure' AttributelowCVSS 3.1EPSS 0.4%
- CVE-2026-33992: PYSEC-2026-497 - pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata ExfiltrationmediumCVSS 4EPSS 0.4%
- CVE-2023-0435: PYSEC-2026-494 - Excessive Attack Surface in pyload-nglowCVSS 3.1EPSS 0.7%
- CVE-2023-0297: PYSEC-2026-498 - Code Injection in pyload-nglowCVSS 3.1EPSS 95.9%
- CVE-2024-39205: PYSEC-2026-499 - pyload-ng vulnerable to RCE with js2py sandbox escapelowCVSS 3.1EPSS 16.5%
- CVE-2025-54802: PYSEC-2026-493 - pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)lowCVSS 3.1EPSS 1.2%
- CVE-2025-53890: PYSEC-2026-496 - pyLoad vulnerable to XSS through insecure CAPTCHAlowCVSS 3.1EPSS 1.2%
- CVE-2026-46561: pyLoad SSRF via HTTP redirect bypass in parse_urls APImediumCVSS 5EPSS 0.3%
- CVE-2026-45348: pyLoad stored XSS in Downloads view via packages.js templatehighCVSS 8.7EPSS 0.4%
Most severe pyload-ng (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-22416: pyLoad pyload-ng CSRF leading to admin privilege escalationcriticalCVSS 9.6EPSS 0.9%
- CVE-2024-47821: pyLoad remote code execution via flashgot API and scripts folder manipulationcriticalCVSS 9.1EPSS 0.7%
- CVE-2026-35459: pyLoad SSRF via HTTP redirect bypass in BaseDownloadercriticalCVSS 9.1EPSS 0.4%
- CVE-2026-41133: pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)highCVSS 8.8EPSS 0.5%
- CVE-2026-45348: pyLoad stored XSS in Downloads view via packages.js templatehighCVSS 8.7EPSS 0.4%
- CVE-2026-42313: pyLoad incorrect authorization in proxy configuration settingshighCVSS 8.3EPSS 0.4%
- CVE-2026-42315: pyLoad path traversal in set_package_data APIhighCVSS 8.1EPSS 0.5%
- CVE-2025-61773: pyLoad CNL and captcha handlers allow Code Injection via unsanitized parametershighCVSS 8.1EPSS 0.4%
- CVE-2026-35187: pyLoad SSRF and local file disclosure in parse_urls APIhighCVSS 7.7EPSS 0.4%
- CVE-2025-7346: pyLoad authentication bypass via Host header spoofing in local_checkhighCVSS 7.5EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 6 | 0 | |
| 6 Jul 2026 | 13 | 0 | |
| 13 Jul 2026 | 2 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 2 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pyload-ng.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "pyload-ng (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pyload-ng, 26 September 2026.