GHSA-p3pr-8f3m-4qp8
## Summary pyLoad ships the WindowsPhoneNotify addon, whose `send()` method opens an HTTP connection to a host taken directly from the plugin's `pushurl` configuration value. A user holding the standard non-admin `SETTINGS` permission can set `pushurl` and `pushid` and enable the addon through the web API, since these plugin options are not in the admin-only option set. Once enabled, the addon activates dynamically without a restart, and any completed download (download events fire globally, not per user) causes the addon to send an HTTP POST to the configured host and path. The request is made with Python's `http.client.HTTPConnection`, so it never passes through pyLoad's pycurl-based outbound connection guard. The attacker can therefore direct blind POST requests at internal hosts such as loopback services, RFC 1918 addresses, or the cloud metadata endpoint `169.254.169.254`. ## Root Cause pyLoad enforces its outbound SSRF protection only inside the pycurl request path, where a `PREREQFUNCTION` callback calls `is_global_address()` on the resolved peer IP before each connection. The WindowsPhoneNotify addon uses a completely separate HTTP client (`http.client.HTTPConnection`) that is never subjected to that callback and performs no address validation of its own. In addition, the API config-write authorization only guards a narrow hard-coded set of plugin options, which does not include the WindowsPhoneNotify host and path fields, so a non-admin user can point the notifier at any destination. ```text Affected symbols: - WindowsPhoneNotify.send (src/pyload/plugins/addons/WindowsPhoneNotify.py): opens http.client.HTTPConnection(url) on the attacker-controlled pushurl with no destination check. - Api.set_config_value (src/pyload/core/api/__init__.py): ADMIN_ONLY_PLUGIN_OPTIONS contains only AntiVirus entries, so a non-admin SETTINGS user can write the WindowsPhoneNotify pushurl, pushid, and enabled values. ``` ## Impact An authenticated user with the non-admin `S
Properties
- severity
- medium
- summary
- pyLoad WindowsPhoneNotify addon: non-admin SETTINGS user triggers SSRF via unguarded http.client notification host
- cvss_score
- 6.4
- retrieved_at
- 2026-10-10T02:17:04+00:00
- ghsa_published
- 2026-10-09T17:09:03Z
- source_url
- https://github.com/advisories/GHSA-p3pr-8f3m-4qp8
- ghsa_updated
- 2026-10-09T17:09:04Z
- ghsa_id
- GHSA-p3pr-8f3m-4qp8
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-p3pr-8f3m-4qp8
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- signal_observed_at
- 2026-10-10T02:17:04+00:00
- is_ghsa_only
- true
Related Entities (4)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph