Junglewise Threat Intelligence

pyload-ng RCE via js2py sandbox escape

Severity: info · CVSS 9.8 · Published 2024-10-28

Technologies: pyLoad Next Generation. Vendors: pyLoad.

Executive brief

pyload-ng is a download manager application that accepts HTTP requests to process encrypted packages. A vulnerability in the underlying js2py JavaScript sandbox library allows unauthenticated attackers to bypass access controls and execute arbitrary shell commands on the server. An attacker can send a crafted HTTP request to trigger remote code execution with full system privileges.

Technical details

The vulnerability exploits CVE-2024-28397, a sandbox escape in the js2py library used by the /flash/addcrypted2 API endpoint. Although the endpoint is designed to accept only localhost connections, attackers can bypass this restriction using HTTP headers (Host header spoofing). An attacker can inject malicious JavaScript code that escapes the js2py sandbox by accessing Python's object model through getattr operations, eventually reaching the subprocess.Popen class to execute arbitrary system commands. The attack requires no authentication or user interaction and works on all Python versions up to 3.11; Python 3.12+ is unaffected because pyload-ng no longer uses js2py in those versions.

Affected products

  • pyload pyload-ng <=0.5.0b3.dev85

Timeline

  • 2024-09-07: disclosed
  • 2024-10-28: other: Duplicate advisory published and then withdrawn

References