Executive brief
A vulnerability in the pyload-ng download manager allows users with limited settings permissions to bypass administrative restrictions and change the server's SSL certificate and key files. By pointing the server to malicious certificate files, an attacker can perform man-in-the-middle attacks to intercept sensitive data, including administrator credentials, when the server restarts. This could lead to a full takeover of the pyload-ng instance and exposure of all user data.
Technical details
An authorization bypass (CWE-863) exists in `src/pyload/core/api/__init__.py` due to a naming mismatch in the `ADMIN_ONLY_CORE_OPTIONS` set. The set incorrectly references `ssl_cert` and `ssl_key` instead of the actual configuration keys `ssl_certfile` and `ssl_keyfile`, while `ssl_certchain` is missing entirely. A network-based attacker with low privileges (SETTINGS permission) can submit a `save_config` request to overwrite these file paths. Upon server restart, the application loads the attacker-specified files, enabling Man-in-the-Middle (MitM) attacks and credential theft. The issue is fixed in version 0.5.0b3.dev97.
Affected products
- pyload pyload-ng < 0.5.0b3.dev97
Timeline
- 2026-04-04: disclosed
- 2026-04-07: advisory: NVD publication date
- 2026-04-08: patched: GitHub Advisory published and reviewed