


Perceptive Security
SOC/SIEM Consultancy

pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at …
Published:
21 april 2026 om 22:00:00
Alert date:
22 april 2026 om 22:11:22
Source:
nvd.nist.gov
Web Technologies, Identity & Access
pyLoad, an open-source Python download manager, has a critical authorization vulnerability in versions up to 0.5.0b3.dev97. The application caches user roles and permissions in sessions at login and continues using these cached values even after administrators change user privileges in the database. This allows logged-in users to retain revoked privileges until logout or session expiry, enabling unauthorized privileged actions. The issue affects core authorization and session consistency mechanisms and cannot be resolved through optional security features. A fix has been implemented in commit e95804fb0d06cbb07d2ba380fc494d9ff89b68c1.
Technical details
Mitigation steps:
Affected products:
pyLoad
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41133
https://github.com/pyload/pyload/commit/e95804fb0d06cbb07d2ba380fc494d9ff89b68c1
https://github.com/pyload/pyload/security/advisories/GHSA-66hx-chf7-3332
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
