Executive brief
pyload-ng is a download manager that automates file downloads. A vulnerability in its archive extraction component allows a malicious download to write files outside of the intended folder. This could allow an attacker to overwrite system files, plant malicious scripts, or disrupt operations if a user downloads a specially crafted archive.
Technical details
The `_safe_extractall` function in `src/pyload/plugins/extractors/UnTar.py` implements a path traversal check using `os.path.commonprefix()`. Because this function performs character-level string comparison rather than path-component comparison, it can be bypassed using sibling directory names that share a common string prefix (e.g., `/downloads/pkg` vs `/downloads/pkg_evil`). An attacker can craft a Tar archive with members containing `..` sequences that resolve to locations outside the extraction directory. Exploitation requires the 'ExtractArchive' addon to be enabled and the victim to download a malicious archive. The vulnerability is addressed in version 0.5.0b3.dev97 by using `os.path.commonpath()`.
Affected products
- pyload pyload-ng < 0.5.0b3.dev97
Timeline
- 2026-04-07: advisory: NVD publication date
- 2026-04-08: disclosed: GitHub Advisory published