Junglewise Threat Intelligence

CVE-2026-35592: pyload-ng path traversal in UnTar extraction

CVE-2026-35592 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Technologies: pyload-ng (PyPI), pyLoad Next Generation. Vendors: PyPI, pyLoad.

Executive brief

pyload-ng is a download manager that automates file downloads. A vulnerability in its archive extraction component allows a malicious download to write files outside of the intended folder. This could allow an attacker to overwrite system files, plant malicious scripts, or disrupt operations if a user downloads a specially crafted archive.

Technical details

The `_safe_extractall` function in `src/pyload/plugins/extractors/UnTar.py` implements a path traversal check using `os.path.commonprefix()`. Because this function performs character-level string comparison rather than path-component comparison, it can be bypassed using sibling directory names that share a common string prefix (e.g., `/downloads/pkg` vs `/downloads/pkg_evil`). An attacker can craft a Tar archive with members containing `..` sequences that resolve to locations outside the extraction directory. Exploitation requires the 'ExtractArchive' addon to be enabled and the victim to download a malicious archive. The vulnerability is addressed in version 0.5.0b3.dev97 by using `os.path.commonpath()`.

Affected products

  • pyload pyload-ng < 0.5.0b3.dev97

Timeline

  • 2026-04-07: advisory: NVD publication date
  • 2026-04-08: disclosed: GitHub Advisory published

References

Related threats