CVE-2026-35464 is a privilege escalation vulnerability in pyLoad, an open-source Python download manager, that allows authenticated users with SETTINGS and ADD permissions to achieve arbitrary code execution. The vulnerability exploits a gap in the security controls implemented to fix a previous vulnerability, specifically the failure to restrict the storage_folder configuration option that can be manipulated to redirect downloads to the Flask session directory. The attack has a HIGH severity rating with CVSS 3.1 score of 7.5, requiring network access and low-level user privileges but achievable with relatively low complexity. An attacker with the noted permissions can plant a malicious pickle payload as a predictable session file and trigger code execution when a corresponding session cookie is presented, resulting in high impact to confidentiality, integrity, and availability. There is currently no indication of active exploitation in the wild. The vulnerability has not been added to the KEV Catalog or designated as a priority on vulnerability hot lists, and the EPSS score of 0.0009 indicates minimal real-world exploitation activity relative to other known vulnerabilities. The issue has been patched via commit c4cf995a2803bdbe388addfc2b0f323277efc0e1, and organizations running pyLoad should prioritize updating to the patched version.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-04-02CPE matchmatch criteria | cpe:2.3:a:pyload:pyload:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.