CVE-2026-32808 is a high-severity path traversal vulnerability (CVSS 8.1) in pyLoad versions before 0.5.0b3.dev97, enabling arbitrary file deletion outside the extraction directory. This flaw, occurring during password verification of encrypted 7z archives, has a network attack vector with low complexity but requires user interaction. The potential impact includes high integrity and availability compromise. Currently, there is no evidence of active exploitation, nor are public exploit codes available. Community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.4.20CPE matchmatch criteria | cpe:2.3:a:pyload:pyload:*:*:*:*:*:*:*:* | ||
>= 0.5.0a5.dev528, < 0.5.0b3.dev97CPE matchmatch criteria | cpe:2.3:a:pyload-ng_project:pyload-ng:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.