Executive brief
pyLoad, a popular open-source download manager, is vulnerable to an authentication bypass. An unauthorized attacker can trick the system into thinking a request is coming from the local server itself by manipulating network headers. This allows the attacker to perform administrative actions, such as creating arbitrary download packages, without needing a username or password.
Technical details
A vulnerability in pyLoad's 'local_check' middleware allows for an authentication bypass via Host header spoofing. The middleware validates whether a request is local by checking if the 'REMOTE_ADDR' is a loopback address or if the 'HTTP_HOST' header matches '127.0.0.1:9666' or '[::1]:9666'. Because the 'Host' header is user-controlled, a remote attacker can set this header to bypass the check. This grants access to restricted routes such as '/flash/add', enabling the creation of arbitrary download packages. The issue is tracked as CVE-2025-7346 and affects versions up to 0.5.0b3.dev88.
Affected products
- pyLoad pyload-ng <= 0.5.0b3.dev88
Timeline
- 2025-07-07: disclosed
- 2025-07-08: advisory: GHSA-x698-5hjm-w2m5 published