← Back to browse · API

CVE-2024-21644

Severity
HIGH
CVSS
7.5
EPSS
0.42173
Risk score
44.76
CISA KEV
No
PoC
No
Published
2024-01-08
Modified
2025-06-17
First seen
2026-08-07
Aliases
EUVD-2024-0387, GHSA-MQPQ-2P68-46FV, PYSEC-2026-1820
Products
pyload:pyload, pyload:pyload < 0.5.0b3.dev77
Sources
euvd EUVD-2024-0387

Description

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0b3.dev77.

References