CVE-2026-42314
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
11/05/2026
Last modified:
11/05/2026
Description
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ after replacement (partial removal), leaving .. which can be exploited when the path is later resolved by the OS. This vulnerability is fixed in 0.5.0b3.dev100.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



