Executive brief
pyload-ng is a download manager application that accepts HTTP requests to process encrypted packages. A vulnerability in the underlying js2py JavaScript sandbox library allows unauthenticated attackers to bypass access controls and execute arbitrary shell commands on the server. An attacker can send a crafted HTTP request to trigger remote code execution with full system privileges.
Technical details
The vulnerability exploits CVE-2024-28397, a sandbox escape in the js2py library used by the /flash/addcrypted2 API endpoint. Although the endpoint is designed to accept only localhost connections, attackers can bypass this restriction using HTTP headers (Host header spoofing). An attacker can inject malicious JavaScript code that escapes the js2py sandbox by accessing Python's object model through getattr operations, eventually reaching the subprocess.Popen class to execute arbitrary system commands. The attack requires no authentication or user interaction and works on all Python versions up to 3.11; Python 3.12+ is unaffected because pyload-ng no longer uses js2py in those versions.
Affected products
- pyload pyload-ng <=0.5.0b3.dev85
Timeline
- 2024-09-07: disclosed
- 2024-10-28: other: Duplicate advisory published and then withdrawn