VDB
KO

package

PyPI / pyload-ng

pkg:pypi/pyload-ng

MEDIUM 4.3 PyPI
GHSA-3wwm-hjv7-23r3

Pyload log Injection via API /json/add_package in add_name parameter

Modified: 7/30/2025

HIGH 7.5 PyPI
GHSA-4744-96p5-mp2j · CVE-2026-35464

pyLoad: Unprotected storage_folder enables arbitrary file write to Flask session store and code execution (Incomplete fix for CVE-2026-33509)

Modified: 4/7/2026

LOW PyPI
GHSA-fj52-5g4h-gmq8

pyLoad's Session Not Invalidated After Permission Changes

Modified: 4/14/2026

HIGH 8.3 PyPI
GHSA-pg67-9wjv-mr85 · CVE-2026-42313, PYSEC-2026-127

pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy via unrestricted `proxy.*` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586)

Modified: 6/8/2026