Detects pyLoad instances before version 0.5.0b3.dev97 where the ClickNLoad localhost restriction can be bypassed by forging the HTTP Host header to 127.0.0.1:9666. This allows unauthenticated remote access to download injection, file write, and JavaScript execution endpoints. The fix replaces the string-based Host header check with proper is_loopback_request() validation.
Is your app exploitable through CVE-2026-33511?
Scan your domain free