highCVSS 8.1Vulnerability

GHSA-68w4-83fh-f2w8

## Summary `Api.getUserData` (legacy) and `Api.get_userdata` are declared with `@permission(Perms.ANY)` and are reachable at `/api/getUserData` and `/api/get_userdata`. Because `Perms.ANY == 0` and pyLoad's permission check is a bitmask AND, that gate is a no-op: **every authenticated account passes, including one holding zero permission bits.** Both methods are thin wrappers around `check_auth()`, which the maintainers deliberately restricted to administrators by omitting `@permission` (no entry in `perm_map`, so `is_authorized()` returns `False` for non-admins). The wrappers undo that protection. An attacker holding the lowest-privileged account in the system therefore has a clean binary oracle on the **administrator password**, with no account lockout anywhere in the codebase, and with the 100 req/min rate limiter bypassable by rotating `X-Forwarded-For`. ## Affected code `src/pyload/core/api/__init__.py:1446` and `:1464` ```python #: Old API @permission(Perms.ANY) @get def getUserData(self, username: str, password: str) -> OldUserData: """ similar to `check_auth` but returns UserData type. """ user = self.check_auth(username, password) ... @permission(Perms.ANY) @get def get_userdata(self, username: str, password: str) -> UserData: user = self.check_auth(username, password) ... ``` ## Root cause `src/pyload/core/api/__init__.py:57` ```python class Perms(IntFlag): ANY = 0 #: requires no permission, but login ``` `src/pyload/core/api/__init__.py:108` ```python def has_permission(user_perms: Perms, required_perms: Perms): return required_perms == (user_perms & required_perms) ``` For `required_perms == 0` this evaluates to `0 == (user_perms & 0)` → `0 == 0` → **always `True`**. The `@permission(Perms.ANY)` gate therefore admits every authenticated principal regardless of which permission bits they hold. Contrast with the intended admin-only primitive, `src/pyl

Properties

summary
pyload-ng: getUserData/get_userdata exposed at Perms.ANY allow any authenticated account to brute-force the administrator password
severity
high
cvss_score
8.1
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T17:09:15Z
source_url
https://github.com/advisories/GHSA-68w4-83fh-f2w8
ghsa_updated
2026-10-09T17:09:16Z
ghsa_id
GHSA-68w4-83fh-f2w8
last_source
GitHub Advisory Database
cve_id
GHSA-68w4-83fh-f2w8
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
true

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Improper Authentication

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/pyload-ng

AFFECTS (1)

→[Software]pip/pyload-ng

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-68w4-83fh-f2w8 (CVSS 8.1) — Ninja Signal Threat Intelligence | Ninja Signal