CVE-2026-45306Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR or userdir, but does NOT protect the Flask session directory (/tmp/pyLoad/flask). An authenticated attacker can set storage_folder to the session directory and download session files of other users via /files/get/, leading to account takeover. This vulnerability is fixed in 0.5.0b3.dev100.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-706

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-28)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-12: 1Mentions · 2026-05-28: 3Patch / Workaround · 2026-05-28: 1Technical Details · 2026-05-28: 105-1205-28
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-121
Disclosure1
2026-05-283
Disclosure2General1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-45306 Authenticated Session File Disclosure in pyLoad Prior to 0.5.0b3.dev100 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45306

    Post summary

    CVE-2026-45306 is disclosed as an authenticated session file disclosure affecting pyLoad prior to 0.5.0b3.dev100; the text provides technical details but no PoC, exploit, active use, patch, or false‑positive claim.

    0000149
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-45306 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR… https://www.cve.org/CVERecord?id=CVE-2026-45306

    Post summary

    The post references CVE‑2026‑45306 and notes a fix for another CVE, but provides no exploit, PoC, active attack, or detailed vulnerability information.

    00010174
    57.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-45306 pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR… https://www.cve.org/CVERecord?id=CVE-2026-45306 ----- Traducción: CVE-2026-45306 pyL… http://infoflow.cloud`

    Post summary

    The tweet notes CVE-2026-45306 affecting pyLoad and references a prior patch for a related issue, but provides no exploitation or mitigation details.

    0000032
    79 followersView on X
  • Ali Saifeldin@Ali_Saifeldin
    Disclosure

    🚨 I discovered an incomplete fix vulnerability in pyLoad (CVE-2026-45306). Advisory: https://github.com/pyload/pyload/security/advisories/GHSA-w727-595x-pc3r #CyberSecurity #BugBounty #AppSec #SecurityResearch #OpenSource #pyLoad

    Post summary

    The tweet announces the discovery of an incomplete fix vulnerability (CVE-2026-45306) in pyLoad and directs readers to an advisory.

    00000102
    194 followersView on X

Explore more