Executive brief
pyLoad is an open-source download manager used to automate file downloads from various hosting sites. A security flaw allows an authenticated user with basic permissions to force the server to make unauthorized requests to internal network resources or read sensitive local files. This could lead to the exposure of internal credentials, cloud metadata, or configuration files, potentially allowing an attacker to gain deeper access to the hosting environment.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the `parse_urls` API endpoint of pyLoad due to insufficient validation of the `url` parameter. The application uses `pycurl` to fetch the provided URL without enforcing protocol restrictions or IP blacklists. An authenticated attacker with 'ADD' permissions can exploit this to perform internal port scanning, access cloud metadata services (e.g., AWS/GCP endpoints), and interact with internal services like Redis or Memcached via `gopher://` or `dict://` protocols. Furthermore, the `file://` protocol can be used to read local system files or perform file existence enumeration via error-based side channels. The vulnerability is addressed in version 0.5.0b3.dev97 by implementing protocol and IP address validation.
Affected products
- pyload pyload-ng <= 0.5.0b3.dev96
Timeline
- 2026-04-01: advisory: GitHub Security Advisory published
- 2026-04-06: disclosed: CVE published to NVD
- 2026-04-06: patched: Fix committed to repository