CVE-2026-32808Disclosure(pyload / pyload)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to path traversal during password verification of certain encrypted 7z archives (encrypted files with non-encrypted headers), causing arbitrary file deletion outside of the extraction directory. During password verification, pyLoad derives an archive entry name from 7z listing output and treats it as a filesystem path without constraining it to the extraction directory. This issue has been fixed in version 0.5.0b3.dev97.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pyload
  • pyload-ng

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
pyloadpyload-ng

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-20: 1Mentions · 2026-05-28: 1Technical Details · 2026-03-20: 1Technical Details · 2026-05-28: 103-2005-28
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Ali shmery@Alishmery2
    Disclosure

    Grateful to share CVE-2026-32808 in pyLoad: Arbitrary File Deletion via Path Traversal during encrypted 7z password verification. CVSS 8.1 HIGH. Registered as EUVD-2026-13435. Discovered with Ali Firas - thesmartshadow / Ali Alakbar - ExeC_IQ. #CVE #OpenSourceSecurity https://t.co/T1Q2RaJ6Z8

    Post summary

    CVE‑2026‑32808 is identified as a high‑severity path traversal flaw that can delete arbitrary files during 7z password verification, with no exploit, patch, or active exploitation mentioned.

    0001053
    13 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32808 pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to path traversal during password verification of ce… https://www.cve.org/CVERecord?id=CVE-2026-32808

    Post summary

    CVE-2026-32808 is a path traversal vulnerability affecting pyLoad versions prior to 0.5.0b3.dev97 during password verification; no PoC, exploit, or patch is mentioned.

    0000081
    56.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apppyloadpyload---
Apppyload-ng_projectpyload-ng-python-

Explore more