Junglewise Threat Intelligence

CVE-2025-7346: pyLoad authentication bypass via Host header spoofing in local_check

CVE-2025-7346 · Severity: high · CVSS 7.5 · Published 2025-07-08

Technologies: pyload-ng (PyPI), pyLoad Next Generation. Vendors: PyPI, pyLoad.

Executive brief

pyLoad, a popular open-source download manager, is vulnerable to an authentication bypass. An unauthorized attacker can trick the system into thinking a request is coming from the local server itself by manipulating network headers. This allows the attacker to perform administrative actions, such as creating arbitrary download packages, without needing a username or password.

Technical details

A vulnerability in pyLoad's 'local_check' middleware allows for an authentication bypass via Host header spoofing. The middleware validates whether a request is local by checking if the 'REMOTE_ADDR' is a loopback address or if the 'HTTP_HOST' header matches '127.0.0.1:9666' or '[::1]:9666'. Because the 'Host' header is user-controlled, a remote attacker can set this header to bypass the check. This grants access to restricted routes such as '/flash/add', enabling the creation of arbitrary download packages. The issue is tracked as CVE-2025-7346 and affects versions up to 0.5.0b3.dev88.

Affected products

  • pyLoad pyload-ng <= 0.5.0b3.dev88

Timeline

  • 2025-07-07: disclosed
  • 2025-07-08: advisory: GHSA-x698-5hjm-w2m5 published

References

Related threats