top of page
perceptive_background_267k.jpg

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/tem…

Published:

27 mei 2026 om 22:00:00

Alert date:

28 mei 2026 om 19:09:38

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

pyLoad, an open-source Python download manager, contains a stored cross-site scripting (XSS) vulnerability prior to version 0.5.0b3.dev100. The vulnerability exists in the packages.js template where stored link URLs are interpolated into HTML without proper escaping. Attackers can inject malicious JavaScript by submitting package links containing single quotes and event handlers, which execute in operators' browsers when viewing the downloads page. The vulnerability is exacerbated by the lack of Content Security Policy restrictions on inline scripts.

Technical details

Mitigation steps:

Affected products:

pyLoad

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page