天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-75597 pyLoad 模板未授权访问与信息泄露漏洞

影响未授权攻击者可访问受保护页面模板并泄露内部变量信息

AI 研判

pyLoad 是 Python 编写的开源下载管理器。在 0.5.0b3.dev101 之前,其 Web 界面 `/web/<path:filename>` 路由渲染 Jinja2 模板时未做认证校验,导致本应受 `@login_required` 保护的页面模板可被未授权访问。同时 handlers.py 中异常属性拼写错误(`exc.desc` 应为 `exc.description`)会在 HTTP 500 响应中泄露内部 Jinja2 变量名。

影响范围

pyLoad

pyLoad 0.5.0b3.dev101 之前的版本;0.5.0b3.dev101 已包含修复补丁。

漏洞详情

漏洞类型为未授权访问与信息泄露。成因是 `/web/<path:filename>` 路由缺少认证装饰器,而其他直接路由均有 `@login_required` 保护,攻击者可直接请求底层模板。结合异常属性拼写错误,500 响应体会暴露内部变量名,且通过 200 与 500 状态差异可枚举有效模板名称。

利用条件与风险

利用无需认证,远程即可触发,可获取模板内容与内部变量信息,为后续攻击提供情报,但本身不直接导致代码执行。

修复建议

升级至 0.5.0b3.dev101 或更高版本;临时缓解可限制 Web 界面访问来源或对相关路由增加认证校验。

原始情报

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the `/web/` route in `src/pyload/webui/app/blueprints/app_blueprint.py` renders Jinja2 templates without any authentication requirement. Every equivalent direct route (`/logs`, `/settings`, `/queue`, `/dashboard`, etc.) is protected by `@login_required`, but the underlying templates for all of these pages are accessible unauthenticated via this endpoint. Combined with an exception attribute typo in `src/pyload/webui/app/handlers.py` (`exc.desc` instead of `exc.description`), internal Jinja2 variable names are leaked in HTTP 500 response bodies to unauthenticated callers. An attacker can also enumerate all valid template names by observing 200 vs 500 response differentiation. Version 0.5.0b3.dev101 contains a patch.