Description
pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution. There is no fix available at the time of publication.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1078 | pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution. There is no fix available at the time of publication. |
Github GHSA |
GHSA-3f7w-p8vr-4v5f | pyLoad allows upload to arbitrary folder lead to RCE |
References
History
Thu, 04 Sep 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:pyload:pyload:*:*:*:*:*:*:*:* |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T02:20:35.649Z
Reserved: 2024-04-19T14:07:11.230Z
Link: CVE-2024-32880
Updated: 2024-04-26T18:45:47.257Z
Status : Analyzed
Published: 2024-04-26T18:15:45.970
Modified: 2025-09-04T14:23:51.593
Link: CVE-2024-32880
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA