CVE-2025-53890: pyLoad vulnerable to remote code execution through js2py onCaptchaResult

Published Jul 14, 2025
·
Updated

Summary An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code allows unauthenticated remote attackers to execute arbitrary code in the client browser and potentially the backend server. Exploitation requires no user interaction or authentication and can result in session hijacking, credential theft, and full system rce.

Details The vulnerable code resides in javascript function onCaptchaResult(result) { eval(result); // Direct execution of attacker-controlled input }

The onCaptchaResult() function directly passes CAPTCHA results (sent from the user) into eval() No sanitization or validation is performed on this input A malicious CAPTCHA result can include JavaScript such as fetch() or childprocess.exec() in environments using NodeJS Attackers can fully hijack sessions and pivot to remote code execution on the server if the environment allows it

Reproduction Methods 1. Official Source Installation: bash git clone https://github.com/pyload/pyload cd pyload git checkout 0.4.20 python -m pip install -e . pyload --userdir=/tmp/pyload

2. Virtual Environment: bash python -m venv pyload-env source pyload-env/bin/activate pip install pyload==0.4.20 pyload

CAPTCHA Endpoint Verification

Technical Clarification: 1. The vulnerable endpoint is actually: /interactive/captcha

2. Complete PoC Request: http POST /interactive/captcha HTTP/1.1 Host: localhost:8000 Content-Type: application/x-www-form-urlencoded

cid=123&response=1%3Balert(document.cookie)

3. Curl Command Correction: bash curl -X POST "http://localhost:8000/interactive/captcha" \ -d "cid=123&response=1%3Balert(document.cookie)"

1. Vulnerable Code Location: The eval() vulnerability is confirmed in: src/pyload/webui/app/static/js/captcha-interactive.user.js

Resources

1. https://github.com/pyload/pyload/commit/909e5c97885237530d1264cfceb5555870eb9546 2. OWASP: Avoid eval() 3. #4586

Other sources

pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code allows unauthenticated remote attackers to execute arbitrary code in the client browser and potentially the backend server. Exploitation requires no user interaction or authentication and can result in session hijacking, credential theft, and full system remote code execution. Commit 909e5c97885237530d1264cfceb5555870eb9546, the patch for the issue, is included in version 0.5.0b3.dev89.

— MITRE

Affected Software

2 affected componentsFixes available
pyload pyload>0.5.0b3.dev89
pip/pyload-ng<0.20
0.20

Event History

Jul 14, 2025
CVE Published
via MITRE·11:57 PM
Data Sourced
via MITRE·11:57 PM
DescriptionSeverityWeakness
Jul 15, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·03:38 PM
Data Sourced
via GitHub·03:38 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-53890?

CVE-2025-53890 is classified as a critical vulnerability due to its potential for remote code execution.

2

How do I fix CVE-2025-53890?

To mitigate CVE-2025-53890, upgrade to the latest version of pyLoad that includes the security patch addressing this vulnerability.

3

Who is affected by CVE-2025-53890?

CVE-2025-53890 affects all versions of pyLoad prior to 0.5.0b3.dev89 that utilize the vulnerable CAPTCHA processing code.

4

Can CVE-2025-53890 be exploited remotely?

Yes, CVE-2025-53890 allows unauthenticated remote attackers to exploit the vulnerability and execute arbitrary code.

5

What type of vulnerability is CVE-2025-53890?

CVE-2025-53890 is an unsafe JavaScript evaluation vulnerability found in pyLoad's CAPTCHA processing.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203