Back to Database
Status published
Critical
CVE-2024-32880
pyLoad allows upload to arbitrary folder lead to RCE
Vulnerability Description
pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution. There is no fix available at the time of publication.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-32880
Credits & Attribution
No credits recorded in the NVD database.
More from pyload
View All →CVE-2025-61773
pyLoad CNL and captcha handlers allow code Injection via unsanitized parameters
High
8.1
CVE-2025-57751
Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
High
7.7
CVE-2025-55156
PyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
High
7.8
CVE-2025-54802
pyLoad CNL Blueprint is vulnerable to Path Traversal through `dlc_path` leading to Remote Code Execution (RCE)
Critical
9.8
CVE-2025-54140
pyLoad has Path Traversal Vulnerability in json/upload Endpoint that allows Arbitrary File Write
High
7.5
Affected Vendor
pyload
View all reports →Affected Software
pyload
Vulnerable Versions:
<= 4.2.0
Timeline
Official Publish:
April 26th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H