CVE-2026-33509Disclosure(pyload / pyload)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch pyload pyload systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

pyLoad is a free and open-source download manager written in Python. From version 0.4.0 to before version 0.5.0b3.dev97, the set_config_value() API endpoint allows users with the non-admin SETTINGS permission to modify any configuration option without restriction. The reconnect.script config option controls a file path that is passed directly to subprocess.run() in the thread manager's reconnect logic. A SETTINGS user can set this to any executable file on the system, achieving Remote Code Execution. The only validation in set_config_value() is a hardcoded check for general.storage_folder — all other security-critical settings including reconnect.script are writable without any allowlist or path restriction. This issue has been patched in version 0.5.0b3.dev97.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pyload
  • pyload-ng

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-28)
  • 6 total mentions across 5 days

Affected systems

Products
pyloadpyload-ng

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-25: 1Mentions · 2026-03-29: 1Mentions · 2026-04-05: 1Mentions · 2026-04-07: 1Mentions · 2026-05-28: 2Patch / Workaround · 2026-04-07: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-29: 1Technical Details · 2026-04-05: 103-2503-2904-0504-0705-28
Signal classification2 categories
Disclosure
350.0%
General
350.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-251
Disclosure1
2026-03-291
Disclosure1
2026-04-051
Disclosure1
2026-04-071
General1
2026-05-282
General2
Full discourse6 posts
  • CVE@CVEnew
    General

    CVE-2026-45306 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR… https://www.cve.org/CVERecord?id=CVE-2026-45306

    Post summary

    The excerpt merely references CVE-2026-45306 for pyLoad and links to its CVE record, offering no concrete information on exploitation or mitigation.

    00010174
    57.5K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-45306 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR… https://www.cve.org/CVERecord?id=CVE-2026-45306 ----- Traducción: CVE-2026-45306 pyL… http://infoflow.cloud`

    Post summary

    The text simply cites the CVE ID for pyLoad and links to its CVE record, with an unrelated note on another CVE's fix, providing no substantive vulnerability or mitigation details.

    0000032
    79 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-35464 pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifyin… https://www.cve.org/CVERecord?id=CVE-2026-35464

    Post summary

    The post merely links to a CVE record and notes a patch for a different CVE, offering no evidence of exploitation, PoC, or detailed technical information.

    00000154
    57.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 pyLoad, RCE, #CVE-2026-33509 (Critical) https://dailycve.com/pyload-rce-cve-2026-33509-critical/

    Post summary

    A new critical Remote Code Execution vulnerability (CVE‑2026‑33509) affecting pyLoad has been disclosed.

    0000039
    175 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `pyLoad` is vulnerable to RCE (CVE-2026-33509) via unrestricted reconnect script configuration, affecting users with SETTINGS permission. #pyLoad #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-33509-pyload-rce-reconnect-script-configuration

    Post summary

    The post announces a new remote code execution vulnerability (CVE‑2026‑33509) in pyLoad caused by an unrestricted reconnect script configuration that permits users with SETTINGS permission to execute arbitrary code.

    0000028
    6 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33509 Remote Code Execution in pyLoad Download Manager via Configuration Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33509

    Post summary

    A new CVE (CVE‑2026‑33509) is announced, describing a Remote Code Execution vulnerability in the pyLoad Download Manager via its configuration endpoint, with a reference link for additional details.

    0000045
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apppyloadpyload---
Apppyload-ng_projectpyload-ng-python-

Explore more