highCVSS 7.5Vulnerability

GHSA-jq7h-wrvp-3rgx

An admin who revokes a user's privileges through the REST API does not actually revoke them, because the session carrying those privileges is never invalidated. pyLoad authorizes each request from values copied into the Flask session at login. set_session in webui/app/helpers.py writes role and perms once, and both login_required and the session branch of apikey_auth read them back from the session rather than from the database. The fix for GHSA-66hx-chf7-3332 handled this by deleting the user's session files, but the call was added only in webui/app/blueprints/json_blueprint.py, at the three WebUI form handlers. Api.set_user_permission and Api.change_password in core/api/__init__.py write to the database and return. Both are exported over /api/<func> and both appear in the OpenAPI spec the project serves at /api, so the documented administration interface takes the unpatched route. I should concede an overlap up front. GHSA-66hx-chf7-3332 does name the core method in its own Details, pointing at set_user_permission and noting that it updates the database role and permission only. What that advisory does not do is name /api/set_user_permission as a reachable route, and it does not mention change_password at all, which is the half I think is new. I ran this against pyload-ng 0.5.0b3.dev101 installed from PyPI, on a real instance with real users. Demoting an admin from role 0 to role 1 with permission 0 by POSTing /api/set_user_permission updated the database immediately. The demoted user's existing session still returned 200 on /api/get_userdir, still loaded /settings, and still wrote reconnect.script through /api/set_config_value, which is the admin-only option CVE-2026-33509 was published for. The identical change through /json/update_users killed that session at once: the same request returned 401 and /settings redirected to the login page. The password path behaves the same way. After POSTing /api/change_password for a user, their old password was refused at

Properties

summary
pyLoad: Privilege revocation and password change through the REST API do not invalidate the user's session
severity
high
cvss_score
7.5
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T17:09:09Z
source_url
https://github.com/advisories/GHSA-jq7h-wrvp-3rgx
ghsa_updated
2026-10-09T17:09:11Z
ghsa_id
GHSA-jq7h-wrvp-3rgx
last_source
GitHub Advisory Database
cve_id
GHSA-jq7h-wrvp-3rgx
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
true

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Insufficient Session Expiration

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/pyload-ng

AFFECTS (1)

→[Software]pip/pyload-ng

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-jq7h-wrvp-3rgx (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal