{"id":"CVE-2023-0057","summary":"Improper Restriction of Rendered UI Layers or Frames in pyload/pyload","details":"Improper Restriction of Rendered UI Layers or Frames in GitHub repository pyload/pyload prior to 0.5.0b3.dev33.","aliases":["GHSA-h8r9-467r-vjjf","PYSEC-2026-904"],"modified":"2026-08-12T03:51:17.516808792Z","published":"2023-01-05T00:00:00Z","database_specific":{"cna_assigner":"@huntrdev","cwe_ids":["CWE-1021"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/0xxx/CVE-2023-0057.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"0.5.0b3.dev33"}]}]},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/12b64f91-d048-490c-94b0-37514b6d694d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/0xxx/CVE-2023-0057.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-0057"},{"type":"FIX","url":"https://github.com/pyload/pyload/commit/bd2a31b7de54570b919aa1581d486e6ee18c0f64"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pyload/pyload","events":[{"introduced":"0"},{"fixed":"bd2a31b7de54570b919aa1581d486e6ee18c0f64"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v0.4.9","v0.4.8","v0.4.7","v0.4.6","v0.4.5","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4","v0.3.2","v0.3.1","v0.3","v0.2.2","v0.2.1","v0.2","v0.1.1","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-0057.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}