CVE-2026-33509 is a high-severity vulnerability (CVSS 8.8) affecting pyLoad versions 0.4.0 to before 0.5.0b3.dev97. It allows non-admin users with SETTINGS permission to achieve Remote Code Execution (RCE) by manipulating the `reconnect.script` configuration option via the set_config_value() API endpoint. This low-complexity attack, requiring only low privileges, can lead to complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit modules, or significant community attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.4, <= 0.4.20CPE matchmatch criteria | cpe:2.3:a:pyload:pyload:*:*:*:*:*:*:*:* | ||
>= 0.5.0a5.dev528, < 0.5.0b3.dev97CPE matchmatch criteria | cpe:2.3:a:pyload-ng_project:pyload-ng:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.