VDB
Sign up
MEDIUM6.5

PYSEC-2026-128

Quick fix

PYSEC-2026-128 — pyload-ng: upgrade to the fixed version with the command below.

pip install --upgrade 'pyload-ng>=0.5.0b3.dev100'

Details

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ after replacement (partial removal), leaving .. which can be exploited when the path is later resolved by the OS. This vulnerability is fixed in 0.5.0b3.dev100.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pyload-ng
Introduced in: 0Fixed in: 0.5.0b3.dev100
Fixpip install --upgrade 'pyload-ng>=0.5.0b3.dev100'

References