CVE-2026-42313 | pyLoad up to 0.5.0b3.dev100 HTTP Call __init__.py set_config_value confused deputy
A vulnerability labeled as critical has been found in pyLoad up to 0.5.0b3.dev100. Affected is the function set_config_value of the file src/pyload/core/api/__init__.py of the component HTTP Call Handler. Executing a manipulation can lead to unintended intermediary.
This vulnerability is registered as CVE-2026-42313. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.