CVE-2024-32880: Pyload
High severity, CVSS 7.2. EPSS: 1.4% chance of exploitation in the next 30 days.
pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution. There is no fix available at the time of publication.
Affected products
- Pyload Pyload: up to and including 0.5.0
Published 2024-04-26. Last modified 2026-06-17.