{"id":"CVE-2023-0057","aliases":["GHSA-h8r9-467r-vjjf","PYSEC-2026-904"],"title":"pyLoad vulnerable to Improper Restriction of Rendered UI Layers or Frames","summary":"pyLoad vulnerable to Improper Restriction of Rendered UI Layers or Frames","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","vendor":"pyload-ng","product":"pyload-ng","ecosystem":"pip","affected":["pyload-ng < 0.5.0b3.dev33"],"patched":["pyload-ng 0.5.0b3.dev33"],"published":"2023-01-05","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-h8r9-467r-vjjf","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-0057"},{"url":"https://github.com/pyload/pyload/commit/bd2a31b7de54570b919aa1581d486e6ee18c0f64"},{"url":"https://github.com/pyload/pyload"},{"url":"https://huntr.dev/bounties/12b64f91-d048-490c-94b0-37514b6d694d"}],"tags":["osv","pip"],"epss":0.0046,"epssPercentile":0.39004,"ingestedAt":"2026-07-08T18:25:50.023Z","slug":"CVE-2023-0057","body":"## Overview\n\nImproper Restriction of Rendered UI Layers or Frames in GitHub repository pyload/pyload prior to 0.5.0b3.dev33.\n\n## Affected packages\n\n- `pyload-ng < 0.5.0b3.dev33`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `pyload-ng 0.5.0b3.dev33`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}