GHSA-68w4-83fh-f2w8
## Summary `Api.getUserData` (legacy) and `Api.get_userdata` are declared with `@permission(Perms.ANY)` and are reachable at `/api/getUserData` and `/api/get_userdata`. Because `Perms.ANY == 0` and pyLoad's permission check is a bitmask AND, that gate is a no-op: **every authenticated account passes, including one holding zero permission bits.** Both methods are thin wrappers around `check_auth()`, which the maintainers deliberately restricted to administrators by omitting `@permission` (no entry in `perm_map`, so `is_authorized()` returns `False` for non-admins). The wrappers undo that protection. An attacker holding the lowest-privileged account in the system therefore has a clean binary oracle on the **administrator password**, with no account lockout anywhere in the codebase, and with the 100 req/min rate limiter bypassable by rotating `X-Forwarded-For`. ## Affected code `src/pyload/core/api/__init__.py:1446` and `:1464` ```python #: Old API @permission(Perms.ANY) @get def getUserData(self, username: str, password: str) -> OldUserData: """ similar to `check_auth` but returns UserData type. """ user = self.check_auth(username, password) ... @permission(Perms.ANY) @get def get_userdata(self, username: str, password: str) -> UserData: user = self.check_auth(username, password) ... ``` ## Root cause `src/pyload/core/api/__init__.py:57` ```python class Perms(IntFlag): ANY = 0 #: requires no permission, but login ``` `src/pyload/core/api/__init__.py:108` ```python def has_permission(user_perms: Perms, required_perms: Perms): return required_perms == (user_perms & required_perms) ``` For `required_perms == 0` this evaluates to `0 == (user_perms & 0)` → `0 == 0` → **always `True`**. The `@permission(Perms.ANY)` gate therefore admits every authenticated principal regardless of which permission bits they hold. Contrast with the intended admin-only primitive, `src/pyl
Properties
- summary
- pyload-ng: getUserData/get_userdata exposed at Perms.ANY allow any authenticated account to brute-force the administrator password
- severity
- high
- cvss_score
- 8.1
- retrieved_at
- 2026-10-10T02:17:04+00:00
- ghsa_published
- 2026-10-09T17:09:15Z
- source_url
- https://github.com/advisories/GHSA-68w4-83fh-f2w8
- ghsa_updated
- 2026-10-09T17:09:16Z
- ghsa_id
- GHSA-68w4-83fh-f2w8
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-68w4-83fh-f2w8
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- signal_observed_at
- 2026-10-10T02:17:04+00:00
- is_ghsa_only
- true
Related Entities (4)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph