
Cloud Vulnerability DB
A community-led vulnerabilities database
pyload, an open-source Download Manager written in pure Python, contains a critical vulnerability (CVE-2024-32880) that was disclosed on April 24, 2024. The vulnerability allows an authenticated user to change the download folder and upload a crafted template to the specified folder, leading to remote code execution. At the time of publication, no fix was available (GitHub Advisory).
The vulnerability exists in the template rendering functionality of pyload. The application allows authenticated users to modify the download folder location and upload files through the /json/add_package endpoint. When combined with the template rendering feature at /render/, this can lead to Server-Side Template Injection (SSTI). The vulnerability has been assigned a CVSS v3.1 base score of 9.1 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, indicating high impact on confidentiality, integrity, and availability (GitHub Advisory).
The vulnerability allows authenticated attackers to execute arbitrary code on the affected system through remote code execution (RCE). This could potentially lead to complete system compromise, affecting all versions of pyload up to and including version 5.0 (GitHub Advisory).
The vulnerability requires authentication to exploit. An attacker needs to first login to the admin page, then change the download folder to the template directory, and upload a crafted template file through the /json/add_package endpoint. The exploit can be triggered by visiting a specific URL pattern (GitHub Advisory).
At the time of disclosure, no official fix or patch was available for this vulnerability. Users should consider implementing additional access controls and monitoring systems until a patch is released (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."