mediumCVSS 5.3Vulnerability

CVE-2026-75597

### Summary The `/web/<path:filename>` route in `src/pyload/webui/app/blueprints/app_blueprint.py` renders Jinja2 templates without any authentication requirement. Every equivalent direct route (`/logs`, `/settings`, `/queue`, `/dashboard`, etc.) is protected by `@login_required`, but the underlying templates for all of these pages are accessible unauthenticated via this endpoint. Combined with an exception attribute typo in `src/pyload/webui/app/handlers.py` (`exc.desc` instead of `exc.description`), internal Jinja2 variable names are leaked in HTTP 500 response bodies to unauthenticated callers. An attacker can also enumerate all valid template names by observing 200 vs 500 response differentiation. ### Details **Bug 1 — Missing authentication on `/web/<path:filename>`** File: `src/pyload/webui/app/blueprints/app_blueprint.py`, lines 32–36 ```python @bp.route("/web/<path:filename>", endpoint="web") def render(filename): # ← no @login_required mimetype = mimetypes.guess_type(filename)[0] or "text/html" data = render_template(filename) return flask.Response(data, mimetype=mimetype) ``` Every other sensitive route in the same file is protected: ```python @bp.route("/logs", ...) @login_required("LIST") # protected @bp.route("/settings", ...) @login_required("SETTINGS") # protected @bp.route("/files", ...) @login_required("DOWNLOAD") # protected ``` The `/web/<path:filename>` route has no such decorator, allowing any unauthenticated HTTP client to render arbitrary templates by supplying their filename in the URL path. **Bug 2 — Exception attribute typo causes internal details in error responses** File: `src/pyload/webui/app/handlers.py`, lines 12–20 ```python def handle_exception_error(exc): try: code = exc.code desc = exc.desc # BUG: attribute does not exist on standard exceptions except AttributeError: # always raised — falls here for every exception code = 500

Properties

severity
medium
summary
pyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo
cvss_score
5.3
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T16:40:30Z
source_url
https://github.com/advisories/GHSA-j92p-c242-7hfx
ghsa_updated
2026-10-09T16:40:31Z
ghsa_id
GHSA-j92p-c242-7hfx
last_source
GitHub Advisory Database
cve_id
CVE-2026-75597
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
false

Related Entities (5)

HAS_WEAKNESS (2)

→[Weakness]Generation of Error Message Containing Sensitive Information
→[Weakness]Missing Authentication for Critical Function

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/pyload-ng

AFFECTS (1)

→[Software]pip/pyload-ng

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75597 (CVSS 5.3) — Ninja Signal Threat Intelligence | Ninja Signal