CVE-2026-75597
### Summary The `/web/<path:filename>` route in `src/pyload/webui/app/blueprints/app_blueprint.py` renders Jinja2 templates without any authentication requirement. Every equivalent direct route (`/logs`, `/settings`, `/queue`, `/dashboard`, etc.) is protected by `@login_required`, but the underlying templates for all of these pages are accessible unauthenticated via this endpoint. Combined with an exception attribute typo in `src/pyload/webui/app/handlers.py` (`exc.desc` instead of `exc.description`), internal Jinja2 variable names are leaked in HTTP 500 response bodies to unauthenticated callers. An attacker can also enumerate all valid template names by observing 200 vs 500 response differentiation. ### Details **Bug 1 — Missing authentication on `/web/<path:filename>`** File: `src/pyload/webui/app/blueprints/app_blueprint.py`, lines 32–36 ```python @bp.route("/web/<path:filename>", endpoint="web") def render(filename): # ← no @login_required mimetype = mimetypes.guess_type(filename)[0] or "text/html" data = render_template(filename) return flask.Response(data, mimetype=mimetype) ``` Every other sensitive route in the same file is protected: ```python @bp.route("/logs", ...) @login_required("LIST") # protected @bp.route("/settings", ...) @login_required("SETTINGS") # protected @bp.route("/files", ...) @login_required("DOWNLOAD") # protected ``` The `/web/<path:filename>` route has no such decorator, allowing any unauthenticated HTTP client to render arbitrary templates by supplying their filename in the URL path. **Bug 2 — Exception attribute typo causes internal details in error responses** File: `src/pyload/webui/app/handlers.py`, lines 12–20 ```python def handle_exception_error(exc): try: code = exc.code desc = exc.desc # BUG: attribute does not exist on standard exceptions except AttributeError: # always raised — falls here for every exception code = 500
Properties
- severity
- medium
- summary
- pyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo
- cvss_score
- 5.3
- retrieved_at
- 2026-10-10T02:17:04+00:00
- ghsa_published
- 2026-10-09T16:40:30Z
- source_url
- https://github.com/advisories/GHSA-j92p-c242-7hfx
- ghsa_updated
- 2026-10-09T16:40:31Z
- ghsa_id
- GHSA-j92p-c242-7hfx
- last_source
- GitHub Advisory Database
- cve_id
- CVE-2026-75597
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- signal_observed_at
- 2026-10-10T02:17:04+00:00
- is_ghsa_only
- false
Related Entities (5)
HAS_WEAKNESS (2)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph