mediumCVSS 6.4Vulnerability

GHSA-p3pr-8f3m-4qp8

## Summary pyLoad ships the WindowsPhoneNotify addon, whose `send()` method opens an HTTP connection to a host taken directly from the plugin's `pushurl` configuration value. A user holding the standard non-admin `SETTINGS` permission can set `pushurl` and `pushid` and enable the addon through the web API, since these plugin options are not in the admin-only option set. Once enabled, the addon activates dynamically without a restart, and any completed download (download events fire globally, not per user) causes the addon to send an HTTP POST to the configured host and path. The request is made with Python's `http.client.HTTPConnection`, so it never passes through pyLoad's pycurl-based outbound connection guard. The attacker can therefore direct blind POST requests at internal hosts such as loopback services, RFC 1918 addresses, or the cloud metadata endpoint `169.254.169.254`. ## Root Cause pyLoad enforces its outbound SSRF protection only inside the pycurl request path, where a `PREREQFUNCTION` callback calls `is_global_address()` on the resolved peer IP before each connection. The WindowsPhoneNotify addon uses a completely separate HTTP client (`http.client.HTTPConnection`) that is never subjected to that callback and performs no address validation of its own. In addition, the API config-write authorization only guards a narrow hard-coded set of plugin options, which does not include the WindowsPhoneNotify host and path fields, so a non-admin user can point the notifier at any destination. ```text Affected symbols: - WindowsPhoneNotify.send (src/pyload/plugins/addons/WindowsPhoneNotify.py): opens http.client.HTTPConnection(url) on the attacker-controlled pushurl with no destination check. - Api.set_config_value (src/pyload/core/api/__init__.py): ADMIN_ONLY_PLUGIN_OPTIONS contains only AntiVirus entries, so a non-admin SETTINGS user can write the WindowsPhoneNotify pushurl, pushid, and enabled values. ``` ## Impact An authenticated user with the non-admin `S

Properties

severity
medium
summary
pyLoad WindowsPhoneNotify addon: non-admin SETTINGS user triggers SSRF via unguarded http.client notification host
cvss_score
6.4
retrieved_at
2026-10-10T02:17:04+00:00
ghsa_published
2026-10-09T17:09:03Z
source_url
https://github.com/advisories/GHSA-p3pr-8f3m-4qp8
ghsa_updated
2026-10-09T17:09:04Z
ghsa_id
GHSA-p3pr-8f3m-4qp8
last_source
GitHub Advisory Database
cve_id
GHSA-p3pr-8f3m-4qp8
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
signal_observed_at
2026-10-10T02:17:04+00:00
is_ghsa_only
true

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/pyload-ng

AFFECTS (1)

→[Software]pip/pyload-ng

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-p3pr-8f3m-4qp8 (CVSS 6.4) — Ninja Signal Threat Intelligence | Ninja Signal