


Perceptive Security
SOC/SIEM Consultancy

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/tem…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 19:09:38
Source:
nvd.nist.gov
Web Technologies
pyLoad, an open-source Python download manager, contains a stored cross-site scripting (XSS) vulnerability prior to version 0.5.0b3.dev100. The vulnerability exists in the packages.js template where stored link URLs are interpolated into HTML without proper escaping. Attackers can inject malicious JavaScript by submitting package links containing single quotes and event handlers, which execute in operators' browsers when viewing the downloads page. The vulnerability is exacerbated by the lack of Content Security Policy restrictions on inline scripts.
Technical details
Mitigation steps:
Affected products:
pyLoad
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45348
https://github.com/pyload/pyload/security/advisories/GHSA-fcjq-435v-jx94
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
