TSS-R-2026-001CVE-2026-32808, on CVE ProgramGHSA-7g4m-8hx2-4qh3EUVD-2026-13435CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), on MITRE CWEvulnerabilityfixed
pyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password Verification
Public record of CVE-2026-32808, a path traversal in pyLoad's encrypted 7z password verification that allowed a file outside the extraction directory to be deleted. Fixed in pyload-ng 0.5.0b3.dev97.
- Product
- pyload-ng
- Fixed in
- 0.5.0b3.dev97
- Published
- Severity
- high